DevOps Engineer
Summary
Build and secure CI/CD pipelines using Docker, Kubernetes, Terraform, and AWS/GCP cloud services, integrating SAST/DAST/SCA tools to shift security left in DevOps workflows.
Overview
We are looking for a DevSecOps Engineer/Specialist with 7-10 years of experience in DevOps Security across:
- Docker and Kubernetes
- Terraform
- Building and modifying CI/CD pipelines
- Implementing and configuring Security Tooling - e.g., Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST).
Responsibilities
Key Tasks and Accountabilities include but is not limited to:
- Ensure successful implementation and embedment of effective DevSecOps solutions (i.e. SAST, DAST, CWPP, SCA, etc.)
- Assist the Engineering and Development teams to build effective and secured CI/CD pipelines, assisting in the configuration and maintenance of the pipelines - shifting security left
- Ensure that capabilities are deployed through a CI/CD pipeline with security requirements adhered to prior to deployment
- Communicate application security features to the engineering and development teams utilising a triad of people, processes, and technology
- Advise engineering teams to consider patterns in software security development and best practice, provide recommendations on approach and automation related to security
- Ensure compliance with Security and Operational risk standards
- Work with theCloud team in the engineering of solutions on AWS Cloud using Infrastructure As Code methods such as Terraform and Ansible
- Proactively monitor and fix vulnerabilities while building a “knowledge base”
Qualifications
Relevant Information Technology Degree or National Diploma
Experience
- 7-10 years working experience
- Experience with Dockers, Git, Jenkins, Kubernetes and GCP/Azure/GCP knowledge.
- Working Experience on Linux based infrastructure.
- Configuration and managing databases such as MySQL, MongoDb.
- Excellent troubleshooting and debugging skills.
- Working knowledge of various tools, open-source technologies, and cloud services.
- Experience in deploying security measures in CI/CD cycle process.
- Awareness of critical concepts in DevOps and Agile Principles / methodology.
- Azure services with good hold on b2c identity manager and azure monitoring
- Certification: Microsoft certified: DevSecOps Lead expert or cleared az400 exam of azure