Security Engineer
The Security Expert will be part of the DSO Team and be responsible for defining and documenting security processes, creating hardening guides and policies, and integrate, configure and manage security tools to facilitate the future DevSecOps ways of working.
The typical tasks includes:
•Provide security expertise and guidance to the DSO teams and Enablement teams.
•Document and drive the adoption of secure engineering best practices.
•Develop and evolve policies around information security.
•Develop scripts to automate security processes.
•Document the use of security tools and processes.
•Establish mechanisms and tools for the security automatization within the SDLC
Must have:
§3-5+ years of experience in the information security field
§3-4+ years of experience performing security testing (SAST, SCA, DAST and security on containers). Preferably experience on Microfocus products as Fortify, WebInspect or Fortify SSC. As well as Sonatype Nexus IQ and Prisma Cloud
§3-4+ years of experience with embedding security into CI/CD pipelines
§3+ years experience with agile methodologies
§3+ years of experience in DevSecOps
§2-3+ years of experience with securing containerized environments (Docker, Kubernetes) and virtual machines.
§2-3+ years experience with Azure
§2+ years of experience with Azure DevOps and GitHub §Scripting skills §Good communication skills
Good to have:
•2-3+ years of experience securing infrastructure in Azure (Best) or AWS via automation
•2+ years of experience in vulnerability management, risk management, etc.
•3+ years of experience as developer •Experience implementing security monitoring, logging and alerting
•Experience on Terraform and Ansible