Information Security Engineer (DevSecOps)

Fisher InvestmentsPlano, TX
1dOnsite

About The Position

It's an exciting time to be a member of the Fisher Investments Technology Department. We're investing in the future of our firm's technology and are building our team to achieve global growth. We are looking for a Information Security Engineer (DevSecOps) to support our Corporate Systems team. If you are looking for an opportunity to make a difference as we develop scalable and strategic solutions to support our global growth, we want to hear from you! The Opportunity: Fisher Investments is growing internationally, and we are looking for an Information Security Engineer (DevSecOps) to join a team that drives future global growth and scale through strategic solutions and continuous innovation. You will help support our firm's diverse departments by building relationships with stakeholders, while consulting and managing a full range of CICD pipeline cyber security controls with technology teams at an Enterprise level. You will contribute to projects that require Information Security DevSecOps experience in application development, release management, and infrastructure as code environments. You will report to the Applications Development Team Lead.

Requirements

  • 5+ years of experience in Technology/Security space
  • 2+ years IT/Information Security Infrastructure & IT Operations experience in two or more of the following areas: DevSecOps CICD Pipeline Development & Management
  • Vulnerability Management & Incident Response
  • Azure/AWS Cloud Environments
  • Identity & Access Management
  • Network Security Management
  • SaaS/PaaS Control Development & Management
  • Public Key Infrastructure Management
  • 1-2 years DevSecOps related disciplines, including:
  • Best Practices for Secure Coding in C#, Java, Python
  • Detection, analysis, and response of insecure code methods and vulnerable dependencies
  • Infrastructure as code for Azure or AWS

Responsibilities

  • Develop and manage the configuration, maintenance, and operations of DevSecOps related security services including GitHub Advanced Security and Terraform
  • Frequent interaction with all Information Security Teams, Technology, Project, and Governance teams to assist and implement Secure CICD pipeline practices, controls, and vulnerability response
  • Use analytical, and technical knowledge, to assess and propose cyber security risk remedies related to DevSecOps
  • Participate actively in development of secure coding standards, principles, architecture and standards, leveraging experience in NIST, CIS, ISO, and other international standards
  • Identify areas for improvement proactively and support the DevSecOps effort in standardizing processes
  • Contribute to the success of the Information Security DevSecOps program within the firm by supporting the various teams and customers in the implementation of good security practices
  • Analyze security controls and make recommendations for changes or improvements
  • Develop and manage initiative level artifacts, including architectural diagrams, implementation planning

Benefits

  • 100% paid medical, dental and vision premiums for you and your qualifying dependents
  • A 50% 401(k) match, up to the IRS maximum
  • 20 days of PTO, plus 10 paid holidays
  • Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service