Epicareer Might not Working Properly
Learn More

DevSecOps Engineer

Salary undisclosed

Checking job availability...

Original
Simplified
We are seeking a talented and experienced DevSecOps Engineer to join our dynamic team. The ideal candidate will possess a strong background in DevSecOps tools, application security and automation. As a DevSecOps Engineer, you will play a crucial role in architecting and implementing secure DevOps practices across our organization. Responsibilities: Implement and maintain DevSecOps tools such as GIT, SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), supply chain security, and dependency scanning solutions. Develop and automate security processes using Python and Go Lang to enhance efficiency and scalability. Collaborate with cross-functional teams to integrate security into the software development lifecycle (SDLC) and CI/CD pipelines. Conduct security assessments, vulnerability scanning, and penetration testing to identify and remediate security vulnerabilities. Provide expertise and guidance on application security best practices and assist in the implementation of secure coding standards. Stay abreast of emerging security threats, industry trends, and best practices in DevSecOps. Requirements: Proven experience in DevSecOps practices, including the implementation and management of DevSecOps tools such as GIT, SAST, DAST, supply chain security, and dependency scanning solutions. Extensive experience in safeguarding software supply chains, ensuring the integrity and security of dependencies and components throughout the development lifecycle. Strong programming skills in Python and Go Lang with experience in automation and scripting. In-depth knowledge of application security principles, common vulnerabilities, and secure coding practices. Experience in GITLAB CI/CD DevSecOps pipeline. To reduce the false positives from SAST and Dependency Scanners. Setting up the Supply chain security controls and practices ensuring the integrity and security of dependencies and components throughout the development lifecycle. Experience with containerization technologies (e.g., Docker, Kubernetes) and cloud platforms (e.g., AWS, Azure, GCP) is a plus. Excellent communication and collaboration skills with the ability to work effectively in a fast-paced, team-oriented environment.