DevSecOps Engineer
200 - 250 PLN/ godz.B2B
SeniorFull-time·B2B
#411271·Dodano 7 dni temu·13
Źródło: nofluffjobs.comTech Stack / Keywords
AppSecPythonLinuxSDLCSASTDASTAzure DevOpsCI/CD PipelinesAIKubernetesTerraformCloud securityAnsible
Wymagania
- 5+ years of professional experience in DevSecOps, Application Security, Infrastructure Security, or a closely related area.
- Strong programming and scripting skills in Python and Linux Shell Scripting.
- Practical experience implementing and operating: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), vulnerability management, dependency and software composition security, and container security.
- Strong knowledge of Application Security and Infrastructure Security concepts and practices.
- Proven experience embedding security controls and automated security checks into Azure DevOps pipelines.
- Understanding of secure software development principles and integrating security into CI/CD processes.
Nice to have:
- Familiarity with AI Security, including LLM-related threats, model security, AI application risks, and secure AI development.
- Experience securing Kubernetes clusters and containerized workloads.
- Knowledge of Infrastructure as Code (IaC), with Terraform preferred.
- Experience with Microsoft Azure and cloud security practices.
- Practical knowledge of container and cloud security.
- Experience creating or maintaining Ansible automation scripts.
Obowiązki
- Build, implement, and continuously improve DevSecOps processes across development and deployment workflows.
- Integrate and operate security testing solutions such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), dependency scanning, vulnerability assessment, and container security tools.
- Create and maintain security automation solutions using Python and Linux Shell Scripting.
- Conduct security reviews and assessments of applications and infrastructure, and coordinate remediation of identified risks.
- Work closely with development, infrastructure, operations, and security teams to incorporate security requirements throughout the SDLC.
- Implement, maintain, and improve security controls within Azure DevOps CI/CD pipelines.
- Contribute to the secure implementation of AI/ML technologies, including AI security assessments, governance, and risk management.
- Define and maintain security guidelines, standards, policies, and best practices for cloud, DevOps, and AI-enabled environments.
- Track new and emerging security threats and translate them into appropriate security controls, mitigations, and engineering improvements.
linkgroup
428 aktywnych ofert