About the job
Senior Development Security Operations Engineer
Position Overview
The Senior Development Security Operations Engineer will be an integral part of the product engineering teams, responsible for the implementation and maintenance of secure, automated, and efficient delivery pipelines. This role adheres to the standards, frameworks, and policies established by the DevSecOps Center of Excellence (CoE).
This hands-on position reports directly to the DevSecOps Manager and collaborates closely with developers, Site Reliability Engineers (SREs), and product managers to facilitate swift, secure deployments, optimize infrastructure costs, and ensure compliance with enterprise security protocols. The engineer will work alongside Principal and Senior Staff DevSecOps engineers for technical mentorship and guidance within the centralized DevSecOps leadership structure.
Key Responsibilities
Execution of Product Line DevSecOps
- Construct and sustain CI/CD pipelines using GitHub Actions, GitLab CI, Jenkins, and ArgoCD for designated product lines.
- Integrate various security testing methods (SAST, SCA, DAST, container scanning) into build and deployment workflows.
- Consistently apply CoE standards, templates, and automation frameworks within product environments.
- Diagnose and address DevSecOps-related issues, escalating intricate challenges to Staff/Principal engineers.
Infrastructure & Automation Management
- Deploy Infrastructure-as-Code solutions using Terraform and CloudFormation for product infrastructure.
- Embrace GitOps methodologies for repeatable and auditable infrastructure provisioning.
- Ensure infrastructure deployments adhere to security guidelines, tagging, and cost-control measures.
Observability, Security & Compliance
- Collaborate with SREs to enhance monitoring, logging, and observability using tools like Prometheus, Grafana, OpenTelemetry, New Relic, and CloudWatch.
- Ensure compliance of pipelines and infrastructure with HIPAA, SOC2, and internal security standards.
- Integrate IAM, KMS, GuardDuty, and Security Hub into workflows to fortify cloud security posture.
Financial Operations & Cost Management
- Implement cost governance practices defined by the CoE within product pipelines.
- Guarantee workloads are tagged appropriately, right-sized, and cost-effective.
- Provide cost visibility to product teams and assist during FinOps reviews.
