Home

Security Engineer DevSecOps at Remote, Remote, USA
Email: [email protected]
From:

anilj,

RBC

[email protected]

Reply to:   [email protected]

Security Engineer DevSecOps

Herndon VA (Hybrid 3 days onsite)

Long Term

Must have active Secret clearance or Higher.

We are looking for a Security Engineer to join our DevSecOps team. In this role, you will work closely with developers, ops engineers, and infosec team members to ensure security is built into our development lifecycle from the start. Responsibilities include:

Performing infrastructure security reviews, threat modeling, and risk analysis for systems built on AWS and deployed via infrastructure-as-code tools like AWS CloudFormation

Implementing and managing security controls within AWS including IAM, VPCs, security groups, WAF, encryption, audit logging, etc.

Performing static and dynamic analysis on source code using tools like Anchor/Grype, SonarQube, and Syft to catch security issues early

Integrating security tools like secrets management, SAST, DAST, and dependency scanning into CI/CD pipelines in GitHub Enterprise and AWS CodePipeline

Building and configuring hardened Linux server images using tools like Packer that follow security best practices

Implementing security monitoring and runtime protection for containers and services running on AWS ECS

Helping define security requirements and compliance controls for regulated workloads built on AWS services like RDS Aurora

Creating and managing infrastructure security policies as code via tools like Open Policy Agent

Triaging and resolving security issues, working with developers and ops teams to implement fixes and improvements

Keeping up-to-date with the latest cloud security best practices and threats

Required Skills/Experience:

5+ years experience in an information, cloud, or infrastructure security role

Deep knowledge of AWS security services and features

Experience with infrastructure-as-code and configuration management tools like Ansible, Terraform, or CloudFormation

Proficiency in Linux administration and security best practices

Knowledge of container and orchestrator security (Docker, Kubernetes, ECS)

Experience with DevSecOps processes and toolchains like GitHub, Jenkins, CodePipeline, etc.

Strong scripting/coding ability (Bash, Python, Go, etc.)

Knowledge of compliance frameworks like PCI, HIPAA, FedRAMP, etc.

Keywords: continuous integration continuous deployment golang Virginia
Security Engineer DevSecOps
[email protected]
[email protected]
View all
Tue Jul 16 19:50:00 UTC 2024

To remove this job post send "job_kill 1565141" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.


Your reply to [email protected] -
To       

Subject   
Message -

Your email id:

Captcha Image:
Captcha Code:


Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]
Time Taken: 1

Location: ,