Description :
Role : Sr. DevSecOps Engineer
Location : Bangalore
Working Hours : 12-9PM
Working Model : Hybrid
Intro :
As a DevSecOps engineer, you will provide technical leadership in the DevSecOps areas of Vulnerability Scanning, Certificate Management, Password Policy Management, Infrastructure As code for Cloud Resource Provisioning, Data Analysis of security monitoring outputs, coordination of Remediation Patching, and other daily Security and Compliance efforts.
Additionally, you will assist in developing an automated security framework for robust deployment tools and processes, leveraging various scripting languages and open-source solutions.
Some of the things you will be doing :
- Familiarity with DevSecOps ecosystem : Terraform, Ansible, GitHub, Jenkins, Azure DevOps, SAST, DAST & SCA
- Terraform, Ansible and AWS, Azure Architecture, Network and Security Certifications
- Familiarity with API Security, Container Security, AWS and Azure Cloud Security
- Knowledge of Cloud Resource Provisioning, Cloud Network and Architecture, Cloud Standards and Policies
- Experience with AWS and Azure Policy, Configuration, and Security Management tools
- Experience with security automation, Cloud resource provisioning
- Expertise in programming and scripting languages like Python, NodeJS, SQL query, bash, powershell, and Java
- Experience with Vulnerable Code remediation
- Experience with Vulnerability Management and executive reporting using PowerBI
What technical skills, experience, and qualifications do you need? :
Prior experience (8-10 years) in a Production Engineering or related positionExperience working with Developers, DevOps, and Engineering teams in a dynamic environment to promote / implement the DevSecOps program throughout the organizationExperience coordinating and performing vulnerability assessments through the use of automated and manual tools (SAST, DAST, IAST etc)Ability to review and analyze vulnerability data to identify security risks to the organization's network, infrastructure, and application's and determine any reported vulnerabilities that are false positivesCapability to prepare security vulnerability and risk management reports for managementLeadership and teaming skills to coordinate remediation of vulnerabilities within established timeframesExperience generating and providing executive reports for vulnerability management across DevSecOps Security ProductsProficiency in Java Programming, Bash, Powershell, Python, Terraform or other scripting languagesFamiliarity with Information Security frameworks / standards (i. CIS, NIST, RFC2196, etc)Comprehension in the security areas of Key Management Systems, Certificate Management, Encryption, Penetration Testing, Vulnerability Scanning, Security and Monitoring tools, etcExperience configuring, implementing, and leveraging computer security and networking diagnostic / monitoring toolsKnowledge of Windows and Linux patch management and related information security functions (authentication, encryption, iptables, SSL, Ciphers, etc)Ability to work with APIs and Plugins to integrate security tools into established CI / CD pipelinesSupport code reviews across all code platformsManage security integration into the SDLC process at CSCHelp evolve CSCs application security functions and servicesResponsible for Security bug intake and remediation process for CSCResponsible for leading the remediation of application vulnerability scanning and penetration testingManage integration with Static Application Security Testing (SAST) Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), Infrastructure as a Code (IaC) scanning, Secret Scanning, and Container Image scanningIdentify security exposures and develop mitigation plansIdentify, report and fix technical debtAssist Manager of Application Security on all application security activitiesBecome a representative for the CSC Information Security programBe productive and participate in security initiatives with minimal supervisionBecomes a subject matter expert for security solutions within the CSC platform, knowledge of SANS 25 and Owasp Top 10Be able to act as a mentor for junior dev, devops and security engineersUse the tools and technologies used throughout CSC InfoSecOwn and document medium / large epics and follow through until completionPresent security solutions to a larger CSC audienceTroubleshoot issues and performance bottlenecksFollow Security best practicesCollaborate with cross functional teams (Engineering, DevOps, Product) while carrying out day-to-day tasksParticipate in requirement gathering with Product / SRE / InfraServicesCollaborate with cross Business Unit teams (CLS, DBS, Corp Tax, TBS) on implementing standardized security solutions and integrationsParticipate in inner sourcing / procurement initiatives within CSCWhat technical skills, experience, and qualifications do you need? :
Strong experience with BI Design and Development for Vuln MgmtBE / BTech DegreeStrong experience in distributed platform development and designStrong foundation in core information security principles and goalsProven expertise in enterprise security solutionsKnowledge on common and emerging security threatsIn-depth knowledge of security best practicesAbility to assist in leading the InfoSec teamExceptional analytical aptitude and attention to detailAbility to lead and project drive multiple security initiativesExcellent communication skillsAbility to explain complex security topics in simple languageAbility to work with Senior LeadershipFast learner / A strong willingness to learnGood team player who is self-motivated and well organized(ref : hirist.tech)