The DevSecOps Architect is a key part of the Agile development team that is responsible for building and maintaining enterprise-grade software in the automotive finance and insurance domain. They are responsible for managing and reducing security risks by developing and maintaining global security controls to integrate into our DevOps pipelines. They are responsible for establishing current and long-term direction to drive our DevSecOps culture. They will also help create or update global policies and standards, provide security guidance on infrastructure designs, and conduct risk assessments.
Essential Responsibilities:
Identify and communicate current and emerging security threats
Review existing security measures and recommend and implement enhancements
Establish and maintain a security incident management playbook
Identify vulnerabilities in existing and proposed architectures and solutions and recommend and implement changes or enhancements
Design and implement enterprise-class security systems for the production environments
Train and educate others in IT security practices
Maintain up-to-date knowledge of emerging security practices and threats by participating in professional education, maintaining personal networks, and participating in professional organizations
Assist in the creation of a well-informed cloud architecture strategy
Monitor and maintain one or more active Kubernetes clusters in a cloud-hosted environment
Respond to technical issues in a timely and professional manner
Education and Experience requirements:
B.S. or M.S. in computer science or a related field, with academic knowledge of IT security and 5 or more years of relevant professional experience, or equivalent combination of education and or experience
Direct participation in the design, implementation, deployment, and maintenance of three or more large-scale IT security projects
Proficient with Identity and Access Management (IAM) frameworks, policies, and technologies
Real-world experience securing and monitoring PaaS/SaaS and cloud-based computing platforms such as Amazon AWS and Microsoft Azure
Experience with containerization technologies such as Docker, Kubernetes, and Rancher
Experience in DevOps development practices, CI/CD pipelines, especially CircleCI
Experience with Infrastructure-As-Code technologies such as Terraform
Windows and Linux operating system usage and administration
Familiarity with NIST, ISO27001/ISO27002, COBIT, and COSO standards
One or more of the following certifications (or comparable):
Comfortable working in fast-changing environments
Self-driven with strong communication and collaboration skills
Nice to have:
Experience with one or more programming languages such as Python, JavaScript, or Go
Experience with document-oriented databases such as MongoDB and CouchDB
Experience with service bus and messaging technologies such as NServiceBus, Amazon SQS, MSMQ, and RabbitMQ
Experience with SAST and DAST tools
Experience dealing with secrets in a Kubernetes environment