Development Security & Operations Engineer

Seaboard MarineMiami, FL
6dOnsite

About The Position

The development, security, and operations (DevSecOps) Engineer ensures that security is a core part of the software development life cycle (SDLC) by integrating security practices and tools into the company development process. They understand and explain to developers and management the security aspect of development and how to build secure codes. Effective interpersonal and communication skills and the ability to work with the security and development teams are required for this role. This position will manage and execute the DevSecOps process daily. It will use tools to perform code scans and verifications and collaborate with the development teams and management to analyze the codes, show remediation steps, and identify areas for improvement. It will also work with developers and operations staff to ensure security is a shared responsibility, maintaining a culture of security awareness. To perform this job successfully, an individual must be able to satisfactorily perform each essential duty. The requirements listed below are representative, but not necessarily a complete list, of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field. In lieu of a degree, a minimum 10 years’ experience in cybersecurity and/or development.
  • Proven experience in a DevOps, cybersecurity, or related role.
  • Proficiency in programming languages such as Python, Java, or Ruby, and scripting languages for automation tasks.
  • Familiarity with CI/CD tools, container orchestration, and infrastructure as code (IaC) tools.
  • A strong understanding of security principles, practices, and tools. This includes knowledge of threat modeling, risk management, security protocols, encryption technologies, and vulnerability assessment.
  • Understanding of risk assessment techniques and security best practices.
  • Skills in securing cloud environments, including experience with cloud service providers like Azure and AWS and understanding of cloud-native security tools and practices.
  • Understanding of network architectures, protocols, and secure network design. Knowledge of system administration is also crucial for securing the underlying infrastructure.
  • Awareness of legal and regulatory requirements related to information security, such as GDPR, HIPAA, and SOC 2.
  • Ability to identify security issues and vulnerabilities and develop effective and efficient solutions or mitigations.
  • Strong communication skills to effectively collaborate with development, operations, and business teams, and to promote a culture of security awareness.
  • Commitment to staying updated with the latest security trends, threats, and technologies, and the willingness to continuously learn and adapt.
  • Skills in handling security breaches and incidents, including the ability to lead or participate in incident response efforts.

Responsibilities

  • Implement and maintain security tools and practices within the CI/CD pipeline.
  • Conduct regular security assessments and vulnerability testing to identify and mitigate risks.
  • Collaborate with software developers to incorporate secure coding practices.
  • Use tools to automate scans, code verification, and other security tasks.
  • Automate security processes to ensure seamless integration into the development workflow.
  • Monitor and respond to security incidents, ensuring rapid and effective resolution.
  • Stay updated with the latest security threats and trends and advise on necessary updates or changes to security protocols.
  • Work with cloud-based infrastructures, ensuring they are securely configured and compliant with industry standards.
  • Promote a culture of security awareness across the organization.
  • Provides IT support for regulatory and compliance activities.
  • Creates helpdesk support tickets.
  • Keeps IT informed on tips and techniques to enhance cyber security posture.
  • Recommends security enhancements.
  • Additional duties as assigned.

Benefits

  • 401(K) Retirement Saving Plan w/ Employer Match
  • Low-Cost Health, Dental & Vision insurance (Starting DAY ONE)
  • Tuition & Certification Reimbursement
  • Paid Time Off – (15 Days; prorated before 1st year)
  • Parental Leave
  • Paid holidays
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service