Share
JOB DESCRIPTION
You will play a role as a security SME covering Application, Operating systems, Network and Compute. You will be part of a core Agile scrum team responsible for the following:
Be a security champion and elevate our CI/CD pipeline to identify, resolve and govern security vulnerabilities.
Establish formal BAVA/DAVA testing processes.
Establish security standard operating procedures.
Establish life cycle management process across entire stack.
Engage with Enterprise IT to enable new application deployment process.
Use Rally to manage development activities.
Develop highly scalable microservices and APIs.
Develop user-friendly interfaces and dashboards.
Write unit, integration, Regression, Security, Soak, and Performance tests
Build instrumentation and metrics for monitoring and alerting systems
Craft supporting documents (release notes, sudo code, etc)
CSDL4E standards
Research and implement new technologies to tackle specific product asks
Design, develop, fix problems and debug software applications and web services
As a member of the software engineering division, you will take an active role in the definition and evolution of standard practices and procedures.
Be responsible for defining and developing tasks associated with the developing, designing and debugging of software applications or operating systems. The work is non-routine and very complex, involving the application of advanced technical/business skills in the area of specialization. You will be a leading contributor individually and as a team member, provide direction and mentoring to junior SW engineers and others.
You will engage with Architects, SW developers and other multi-functional teams supporting the fast growth of our private Cloud Services
From a technical perspective, you meet the following requirements:
You are experienced in the following disciplines:
In-depth experience identifying and protecting against web application vulnerabilities
Strong knowledge of browser security model, mobile app security, crypto and network security
Experience with security tools for static analysis, dynamic analysis, penetration testing, intrusion detection
Understand and interpret corporate policies, standard methodologies, and results from security reviews and audits
Develop and build security tools and processes for scanning, testing, monitoring and reporting
Conduct vulnerability and risk assessments to provide actionable remediation plans
Develop technical security specifications for targeted cloud applications/workloads
Stay ahead of emerging security threats and solution technologies
IaaS, Paas, CaaS, FaaS, SaaS
Cloud Provider offerings
Building CI/CD framework
Test automation with Jenkins
Management of repositories (Git, SVN, etc...)
DevOps models
Experience in implementing the following technologies/offerings:
Containerization of lightweight applications
Cloud providers - AWS, Azure, Google, Rackspace, etc...
Cloud technologies - Kubernetes, Openshift, DC/OS, ECS, Cattle, Kontena, Docker Swarm, Cloud Foundry, etc...
These jobs might be a good fit