Build and implement DevSecOps processes, governance, and reporting.
Responsible for creating and maintaining DevSecOps policies and processes.
Perform and coordinate internal and externalsecurity audits of code, and applications.
Implement and administer tools for DevSecOps as well as determine best tools for additional security needs for the company.
Work with developers to communicate and track critical security vulnerabilities within application code.
Align with technological Systems/Software Development Life Cycle (SDLC) processes and industry-standard service management principles (such as ITIL)
Consult on DevSecOps requirements from diverse application/line of business partners.
Create plug-and-play/reusable solutions and patterns for CICD pipelines
Create, develop, and implement automation and system integration for various build platforms.
Publish and disseminate CICD best practices, patterns, and solutions.
Requirements:
Strong project management and technical background
8+ years of related cybersecurity experience
3+ years of experience in Leading a DevSecOps Team
Comprehensive technical expertise in a variety of DevSecOps toolkits, including Ansible, Jenkins, Artifactory, Jira, Black Duck, Terraform, Git/Version Control Software, or comparable technologies.
Familiarity with information security frameworks and standards
Knowledge of DevOps Automation (Terraform, GitHub, GitHub Actions)
Experience with security automation and machine learning.
Proven capacity for thinking leadership and a highly creative problem- solver.
Required Education:
Bachelor's degree in computer science, Information Systems, or related field
Preferred Qualifications:
Experience working with DevOps methodologies.
Ability to work with APIs to integrate security tooling into CI/CD pipelines, reporting, and automated processes.
CISM, CISSP or other Security Certifications
Auditing and Compliance Certifications such as CISA, PCI-ISA, and PCIP
Soft Skills
Excellent communication, interpersonal and relationship-building skills
Self-directed
Record of building effective relationships throughout the organization