Job Title: DevSecOps Engineer
Location: Remote
Duration: 6+ months contract
The Position
The Senior Engineer - Application Security will drive application security and secure DevOps processes, along with other key security disciplines throughout all environments. This engineer will partner with teams in establishing secure coding practices as well as helping to influence what good security looks like. This position is critical to establishing and maintaining secure applications while simultaneously promoting a culture of rapid and reliable software across the company. The Application Security Engineer, in conjunction with the rest of the team, will work with various development and operations to deliver the best-in-class applications for our customers that create opportunities to grow.
You will:
- Be a part of a bleeding edge security organization which enables the agile development of secure and reliable applications and products.
- Deploy and tune code scanning solutions such as SAST, DAST, and IAST.
- Interpret code scanning results to ensure the team is focused on remediation of the highest risk vulnerabilities.
- Perform threat modeling of applications to identify potential threat vectors in the technology stack that could be used by attackers and cause disruption or a potential data breach.
- Collaborate with technology stakeholders to establish metrics that demonstrate application security proficiency across all engineering teams.
- Steer the development of tools to improve the security of applications through automation and other means, allowing for faster and easier security gains by teams.
- Ensure processes associated with key systems are documented, maintained, and archived.
You have:
- Proficient experience in software development such as Python, JavaScript, or Java
- Familiarity with security tools such as Nessus, Burp, and web application firewalls.
- Experience with Static/Dynamic Application Security Testing methodologies and tools.
- Experience with automation tools such as Terraform, Puppet, Chef, Salt, Ansible, or CloudFormation.
- Experience conducting a detailed threat model exercise.
- Experience with CI/CD pipelines and how to assess them from a security perspective, including the integration of security tools with the pipeline.
- Experience working with cloud-based infrastructure and technologies, preferably AWS
You are:
- A collaborator who will partner across the engineering organization to drive the establishment of a security posture.
- Results oriented and believes in steady continuous improvement.
- Curious and always go beyond what is happening to discover why.
- An effective communicator with a solution-oriented mindset.
- A strategic thinker who focuses on integrating current initiatives and ideating on ways to improve while still meeting the needs of the business.