About the job
As a Senior DevSecOps Engineer at Forbes Advisor, you will play a pivotal role in integrating security within our DevOps practices. You will design and implement secure CI/CD pipelines, automate secure cloud infrastructure, and ensure compliance across our development, operations, and security teams.
Key Responsibilities
- Design, construct, and maintain secure CI/CD pipelines, leveraging DevSecOps principles to enhance automation and minimize manual intervention.
- Integrate security tools such as SAST, DAST, and SCA within these pipelines to facilitate automated application building, testing, securing, and deployment.
- Implement robust security controls for cloud platforms (AWS, GCP), focusing on IAM, container security (EKS/ECS), and data encryption for services like S3 and BigQuery.
- Automate vulnerability scanning, monitoring, and compliance processes by collaborating closely with the DevOps and Development teams to mitigate risks in deployment pipelines.
- Propose architectural enhancements and recommend process improvements for better efficiency and security.
- Review cloud deployment architectures and implement necessary security measures.
- Mentor fellow engineers on best practices in security.
Qualifications
- Bachelor's degree in Computer Science or a related field, or equivalent practical experience.
- 10+ years of industry experience, with AWS Security Specialist certification.
- Hands-on experience with security tools and processes relevant to SAST, DAST, and Penetration Testing.
- 5+ years of experience with a wide range of AWS technologies (e.g., EC2, RDS, ELB, S3, VPC, CloudWatch) to develop and maintain cloud solutions, with a strong emphasis on cloud security best practices.
- Proficient with CI/CD tools (e.g., GitHub Actions, Jenkins).
- Driven by a passion for solving security challenges and staying updated on current and emerging security threats and technologies.
- Familiarity with the OWASP Top 10 Security Risks and Controls.
- Proficiency in one or more scripting languages, such as Python or Bash.
- Solid understanding of Kubernetes, Docker Swarm, or other container orchestration tools.
- Willingness to work in shifts as necessary.
Preferred Qualifications
- AWS Certified DevOps Engineer.
- Experience with system monitoring tools (e.g., CloudWatch, New Relic).
- Familiarity with automation tools such as Terraform, Ansible, Chef, or Puppet.
- System administration experience with Windows and Linux environments.
Benefits:
- Enjoy a day off on the 3rd Friday of every month for a long weekend.
- Participate in our Monthly Wellness Reimbursement Program to support your health and well-being.
- Benefit from our Monthly Office Commutation Reimbursement Program.
- Receive paid maternity and paternity leave.
