CYBER SECURITY SPECIALIST: DevSecOps, IT CYBER SECURITY

Boardroom Appointments

Cape Town

On-site

ZAR 900,000 - 1,200,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Boardroom Appointments seeks a Cyber Security Specialist with DevSecOps expertise to secure product development and automate security in CI/CD pipelines. You will lead threat modelling, secure coding practices, and vulnerability management, while providing AppSec training and defining security standards across teams.

The role requires hands-on security testing, container/Cloud security experience (AWS/Azure), and strong collaboration with the SecOps team to advance security initiatives within

Qualifications

  • 3-year IT or NQF aligned qualification in IT or security.
  • Minimum 5 years of cyber security experience, with 3 years in DevSecOps.
  • Hands-on experience integrating security into CI/CD and SDLC.
  • Experience with secure coding and app security testing.

Responsibilities

  • Secure product development by embedding security early in SDLC.
  • Maintain and enhance toolsets for mature product security including pen testing and secure coding.
  • Verify security of internal and external apps during development and deployment.
  • Perform threat modelling and strengthen infrastructure, platform, and app security.
  • Provide AppSec training and create learning materials.
  • Define documentation and standards for application security processes.
  • Guide and enhance CI/CD security tooling for cloud platforms (AWS/Azure).
  • Collaborate with SecOps and stakeholders to drive security initiatives.

Skills

DevSecOps
CI/CD security
AppSec
Threat modelling
Cloud security
Automation
Vulnerability management
Security testing
SAST/DAST
Container security

Education

3-year IT or NQF aligned Qualification

Tools

AWS
Azure
Terraform
SonarCube
CI/CD tooling
Containerization

Job description

CYBER SECURITY SPECIALIST: DevSecOps, IT CYBER SECURITY

Job Openings CYBER SECURITY SPECIALIST: DevSecOps, IT CYBER SECURITY

About the job CYBER SECURITY SPECIALIST: DevSecOps, IT CYBER SECURITY

Job Description

  • Secure the development of products - integrate security practices as early as possible in the lifecycle of software development under the guiding principles of shift left and security by default.
  • Prescribe, maintain and enhance cool toolsets manage the relevant tools required for mature product security that include pen testing, secure coding, and source code analysis. Investigate new approaches, technology, and automation to challenge traditional thinking and raise the level of security.
  • Verify the security of internally and externally developed applications and services during and after development and deployment. Actively participate in the SDLC though guidance, education, input, and facilitation.
  • Perform threat modelling enhance and optimize infrastructure, platform, application, and mobile security by identifying threats, vulnerabilities, and associated countermeasures.
  • Provide AppSec training and raise the awareness banner high create and manage learning and reference materials and exercises.
  • Define and implement documentation and standards on application security processes, tooling, and other resources to assist collaboration with the various stakeholder across company.
  • Provide expert guidance on, and where relevant maintain and enhance the toolsets required for mature application security covering secure coding, source code analysis and vulnerability management.
  • Investigate new approaches, technologies, and automation to mature AppSec.

Additional Responsibilities:

  • Collaborate with the broader SecOps Team to drive and support various operational and strategic initiatives.
  • Champion or co-champion internal security solutions and/or processes.

Mandatory

  • 3-year IT or NQF aligned Qualification
  • 5 years relevant experience in cyber security, with at least 3 years in a DevOps / DevSecOps capacity.
  • Hands on practical experience in DevOps / DevSecOps and the ability to integrate security into the CI/CD processes
  • Hands on practical experience in application security testing.
  • Extensive knowledge of DevSecOps principles, practices, and tools, including containerization, orchestration, and automation.
  • Experience in securing CI/CD pipelines on Cloud platforms, specifically AWS and Azure.
  • Experience with infrastructure-as-code tools (e.g., Terraform).
  • Solid experience in Secure Code Development practices and tools, e.g., SonarCube.
  • Good understanding of common security libraries, frameworks, and tools.
  • Ability to explain the common security flaws as well as potential ways to address them.
  • Deep technical skills and ability to automate manual processes.
  • Bloodhound approach to security.
  • Relentless pursuit of threat identification and remediation.
  • Relevant research and translation into defence.
  • Very good people skills to engage with the various stakeholders across the business, while ensuring that professionalism is maintained.
  • Ability to engage with and contribute to the Information Security community.

Additional Criteria

  • Relevant qualifications and certifications such as SANS (SEC 540 or SEC 534), GIAC GCSA or the AWS Developer Associate certification is highly advantageous.
  • Practical experience with the MITRE ATT&CK framework is advantageous.
  • May be required to assist outside of working hours.
  • Knowledge of company IT and cyber security landscape, including systemic understanding of key business linkages and dependencies
  • Is aware of and responsive to internal and external events and influences on the technical landscape
  • Ability to research technology-related concepts, trends, and best practices, and apply findings
  • Appropriately derives and organises the essence of information to draw solid conclusions
  • Looks beyond symptoms to uncover root causes of problems to be solved
  • Synthesises data from different sources to identify trends
  • Presents problem analysis and a recommended solution rather than just identifying and describing the problem itself
  • Proactively approaches others to obtain missing information
  • Demonstrates a results-oriented mindset in planning and implementing activities/projects
  • Clearly defines objectives and translates them into workable activities
  • Monitors and tracks progress to ensure delivery of all planned commitments, and keeps the appropriate people informed
  • Prepares written reports and briefs and communicates ideas clearly
  • Speaks fluently in team meetings when presenting information
  • Manages existing partnerships within established agreements or contracts; negotiates adjustments when mutually beneficial to do so
  • Genuinely cultivates personal bonds with colleagues to enhance performance throughout the organisation
  • Adjusts to work effectively within new work structures, processes, requirements, or cultures
  • Demonstrates resourcefulness in acquiring necessary knowledge, skills, and competencies to adapt to change
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps Engineer
DevOps Engineer

Samaha Consulting • City of Johannesburg Metropolitan Municipality

On-site
ZAR 900,000 - 1,500,000
Cyber Security Technical Manager
Cyber Security Technical Manager

Boardroom Appointments • Johannesburg

On-site
ZAR 1,200,000 - 1,800,000
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

Adeo South Africa Limited • Gauteng

On-site
ZAR 900,000 - 1,500,000
Security Analyst
Security Analyst

Adapt IT Group • Midrand

On-site
ZAR 600,000 - 900,000
Senior Security Analyst - Hybrid
Senior Security Analyst - Hybrid

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,200,000
Security Defence & Operations Lead
Security Defence & Operations Lead

Salix Recruitment • Gauteng

On-site
ZAR 1,200,000 - 1,900,000
Senior Security Analyst
Senior Security Analyst

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,600,000
Senior Cloud Security & DevSecOps Manager
Senior Cloud Security & DevSecOps Manager

Optimal Growth Technologies • Johannesburg

Hybrid
ZAR 1,000,000 - 1,500,000
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

ATS Client • Sandton

On-site
ZAR 900,000 - 1,600,000