IT Cloud Cybersecurity Senior Manager

The Boston Consulting Group (BCG)Washington, DC
268d

About The Position

BCG Federal is a US federally compliant environment at BCG. The BCG FED Organization is seeking a knowledgeable and talented Lead Cyber Security Cloud Engineer that will be responsible for operating and maintaining the BCG Cybersecurity DevSecOps programs in alignment with NIST 800-171, CMMC and IT Security best practices. The DevSecOps Lead manages the DevSecOps environment, and internal playbooks relating to IT Cloud security. They will ensure appropriate application of DevSecOps methodologies, security products, and technologies to protect the company's systems and information.

Requirements

  • Minimum of 5 years of information security experience.
  • Strong background in agile software development such as DevSecOps, CI/CD pipelines, Kubernetes, Docker, Terraform, Python, and Azure GCCH.
  • Experience with the management of DevSecOps, Azure GCCH and Gitlab/Github environments.
  • Experience with CI/CD, software composition analysis, SAST and DAST tools and processes.
  • Technical knowledge and hands on experience with Azure GCCH and Gitlab, Terraform, Python, Kubernetes, and Docker services and technologies.
  • Experience working with the Microsoft G5 Security stack.
  • Must be able to obtain and maintain a U.S. government security clearance.
  • U.S. Citizenship Required.

Responsibilities

  • Operating IAW with relevant industry standards and frameworks (i.e. FedRAMP, NIST 800-171, CMMC, etc) while embedding agile DevSecOps.
  • Be the subject matter expert (SME) for all things DevSecOps and SDLC in the environment.
  • Manage BCG Federal's DevSecOps day to day operations ensuring continuous security integration within agile workflows, monitoring, and implementation of security technologies related to DevSecOps.
  • Overseeing the management, monitoring, and implementation of security technologies across CI/CD pipelines to maintain a continuous security posture.
  • Understanding the current threat landscape and helping to develop risk mitigation strategies.
  • Creation of documentation and knowledgebase articles regarding DevSecOps policies and procedures.
  • Provide monthly reporting metrics on DevSecOps environment, including indicators of continuous security improvements and performance.
  • Assist with development of the company's DevSecOps processes and procedures.
  • Create KPI's, metrics, dashboards and reporting to measure the performance of the DevSecOps environment.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service