Design, build and maintain secure CI/CD pipelines utilizing DevSecOps principles and practices to increase automation and reduce human involvement in the process
Integrate tools of SAST, DAST, SCA, etc. within pipelines to enable automated application building, testing, securing and deployment.
Implement security controls for cloud platforms (AWS, GCP), including IAM, container security (EKS/ECS), and data encryption for services like S3 or BigQuery, etc.
Automate vulnerability scanning, monitoring, and compliance processes by collaborating with DevOps and Development teams to minimize risks in deployment pipelines.
Suggesting architecture improvements, recommending process improvements.
Review cloud deployment architectures and implement required security controls.
Mentor other engineers on security practices and processes.
Requirements
Bachelor's degree, preferably in CS or a related field, or equivalent experience
10+ years of overall industry experience with AWS Certified - Security Specialist.
Must have implementation experience using security tools and processes related to SAST, DAST and Pen Testing
AWS-specific: 5+ years’ experience with using a broad range of AWS technologies (e.g. EC2, RDS, ELB, S3, VPC, CloudWatch) to develop and maintain an Amazon AWS based cloud solution, with an emphasis on best practice cloud security.
Experienced with CI/CD tool chain (GitHub Actions, Packages, Jenkins, etc.)
Passionate about solving security challenges and being informed of available and emerging security threats and various security technologies.
Must be familiar with the OWASP Top 10 Security Risks and Controls
Good skills in at least or more scripting languages: Python, Bash
Good knowledge in Kubernetes, Docker Swarm or other cluster management software.
Willing to work in shifts as required
Good to Have
AWS Certified DevOps Engineer
Observability: Experience with system monitoring tools (e.g. CloudWatch, New Relic, etc.).
Experience with Terraform/Ansible/Chef/Puppet
Operating Systems: Windows and Linux system administration.
Perks:
Day off on the 3rd Friday of every month (one long weekend each month)
Monthly Wellness Reimbursement Program to promote health well-being
Monthly Office Commutation Reimbursement Program
Paid paternity and maternity leaves
Key Requirements & Skills
Bachelor's degree, preferably in CS or a related field, or equivalent experience
10+ years of overall industry experience with AWS Certified - Security Specialist.
Must have implementation experience using security tools and processes related to SAST, DAST and Pen Testing
AWS-specific: 5+ years’ experience with using a broad range of AWS technologies (e.g. EC2, RDS, ELB, S3, VPC, CloudWatch) to develop and maintain an Amazon AWS based cloud solution, with an emphasis o
Experienced with CI/CD tool chain (GitHub Actions, Packages, Jenkins, etc.)
Passionate about solving security challenges and being informed of available and emerging security threats and various security technologies.
Must be familiar with the OWASP Top 10 Security Risks and Controls
Good skills in at least or more scripting languages: Python, Bash
Good knowledge in Kubernetes, Docker Swarm or other cluster management software.
Willing to work in shifts as required
AWS Certified DevOps Engineer
Observability: Experience with system monitoring tools (e.g. CloudWatch, New Relic, etc.).
Experience with Terraform/Ansible/Chef/Puppet
Operating Systems: Windows and Linux system administration.
Frequently Asked Questions
How to apply for DevSecOps – Staff Engineer at Forbes Advisor?
Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.
What is the salary for this role?
Salary details will be discussed during the interview.