Requirements
Experience:
聽
路聽8+ relevant experience in Cyber Security, Cloud Security, Application Security, or DevSecOps engineering roles.
聽
Key Responsibilities:
聽
路聽Conduct comprehensive DevSecOps security discovery, assessment, and risk evaluation activities across cloud platforms, applications, and development environments.
路聽Perform security posture reviews using Orca Security and GitHub Advanced Security to identify vulnerabilities, misconfigurations, exposed assets, code security issues, and compliance gaps.
路聽Analyse cloud workloads, repositories, infrastructure configurations, and application architectures to assess security risks and recommend mitigation strategies.
路聽Partner with DevOps, engineering, and application teams to integrate security controls and secure-by-design principles throughout the software development lifecycle (SDLC).
路聽Implement and enhance security capabilities within CI/CD pipelines, including automated security testing, code scanning, secret detection, dependency analysis, and policy enforcement.
路聽Review and validate security findings, prioritize risks based on business impact, and provide actionable remediation guidance to stakeholders.
路聽Track remediation efforts and security improvements across cloud environments, containerized workloads, and source code repositories.
路聽Support vulnerability management activities, including identification, reporting, risk assessment, and remediation verification.
路聽Contribute to the development of DevSecOps standards, security baselines, governance frameworks, and operational procedures.
路聽Collaborate with cross-functional teams to improve cloud security architecture, compliance readiness, and security monitoring capabilities.
路聽Prepare assessment reports, security dashboards, executive summaries, and technical recommendations for management and project teams.
聽
Required Skills and Experience:
聽
路聽Strong hands-on experience with Orca Security and GitHub Advanced Security.
路聽Practical knowledge of DevSecOps methodologies, security automation, and secure software development practices.
路聽Experience securing CI/CD platforms and integrating security controls into development pipelines.
路聽Strong understanding of cloud security concepts, including identity and access management, network security, data protection, and workload security.
聽
路聽Experience with vulnerability management, risk assessment, and remediation tracking.
路聽Knowledge of application security principles, code security testing, and software supply chain security.
路聽Familiarity with cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).
路聽Understanding of container security, Kubernetes security, and Infrastructure as Code (IaC) security practices.
路聽Strong analytical, troubleshooting, and problem-solving skills.
路聽Excellent communication and stakeholder management capabilities.
聽
Preferred Qualifications:
聽
路聽Relevant cloud security or cybersecurity certifications.
路聽Experience working in enterprise-scale DevSecOps and cloud transformation programs.
路聽Knowledge of regulatory compliance frameworks and industry security standards.
聽
Education:
聽
路聽Bachelor鈥檚 degree in computer science, Information Security, Information Technology, Engineering, or a related field.
Learn more about this Employer on their Career Site
