Role: The organization is looking for a DevSecOps Security Engineer with a focus on OWASP MITRE SOC 2 and NIST philosophy and compliance. The candidate should have experience with GitHub GitHub Actions Dependabot Azure and AWS with at least basic familiarity with PHP and Ruby on Rails.
Responsibilities:
Develop and maintain DevSecOps practices and tools to ensure security and compliance.
Implement and enforce OWASP MITRE SOC 2 and NIST security best practices and frameworks.
Conduct security assessments vulnerability scans and penetration testing.
Collaborate with development teams to integrate security into the CI/CD pipeline and automate security testing and compliance checks.
Manage and maintain security tools including WAFs IDS/IPS and vulnerability scanners.
Respond to security incidents and perform root cause analysis.
Stay uptodate with the latest security threats trends and technologies.
Requirements
Requirements:
BS/MS in Computer Science Information Security or a related field.
58 years of experience in DevSecOps security engineering or a related field.
Familiarity with OWASP MITRE SOC 2 and NIST security frameworks and best practices.
At least basic familiarity with PHP and Ruby on Rails development.
Experience with GitHub GitHub Actions and Dependabot for code management and security.
Experience with Azure and AWS for infrastructure management and security.
Understanding of security compliance and regulatory requirements.
Problemsolving communication and collaboration skills. Experience with security tools including WAFs IDS/IPS and vulnerability scanners.
Incident response and root cause analysis experience.
Preferred:
CISSP CISA or related certification.
Experience with containerization and orchestration technologies especially Kubernetes.
Experience with IaC tools.
Familiarity with DevOps practices
Benefits
Medical & Life insurance
Motivating compensation
Paid Holidays
Great working environment
Rapid career development opportunities
5-8 years of experience in DevSecOps, security engineering, or a related field. Familiarity with OWASP, MITRE, SOC 2, and NIST security frameworks and best practices. At least basic familiarity with PHP and Ruby on Rails development.
Education
BS/MS in Computer Science, Information Security, or a related field.