Securing CI/CD Pipelines:
- Implement and manage security controls for CI/CD pipelines.
- Automate security testing and vulnerability management within the CI/CD process using tools like Terraform.
- Collaborate with development teams to integrate security best practices and policies.
Working with WAFs:
- Configure and manage Web Application Firewalls (WAFs) such as Cloudflare to protect web applications from security threats.
- Monitor and update WAF rules to respond to new vulnerabilities and attack vectors.
- Conduct regular security assessments and audits of WAF configurations.
Cloud Security Posture Management:
- Develop and implement cloud security best practices and policies.
- Continuously monitor cloud environments using tools like AWS Guard Duty, Wiz, Orca, WAF, Cloudflare and similar to ensure compliance with security standards.
- Collaborate with cloud operations teams to identify and remediate security risks.
- Managing security cloud configuration with tools like Terraform and CDK
Implementing Security Self Service approach:
- Development security tools in the organization IDP
- Testing/performing PoC of new security tools to increase efficiency development practices in the security context and foster Secure by Design principle.