DevSecOps Engineer
Responsibilities
Design, implement, and maintain secure CI/CD pipelines, integrating security tools and best practices at every stage
Automate infrastructure provisioning, configuration, and management using Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation, Ansible)
Implement and manage security tools for vulnerability scanning, static/dynamic code analysis, and penetration testing
Collaborate with development teams to integrate security into the development process (e.g., SAST/DAST integration, code reviews)
Develop and maintain security, hardening standards and guidelines for various systems and applications
Monitor and analyze security alerts and logs and respond to security incidents
Champion a DevSecOps culture by promoting security awareness and best practices across the organization
Continuously research and evaluate new security technologies and tools
Mentor and guide junior engineers on DevSecOps best practices
Participate in on-call rotation for production support
Contribute to the improvement of our overall security posture
Job description
DevSecOps Engineer
Location: WALTHAM, MA
Experience (Years): 6-8
Role Description:
Design, implement, and maintain secure CI/CD pipelines, integrating security tools and best practices at every stage.Automate infrastructure provisioning, configuration, and management using Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation, Ansible).
Implement and manage security tools for vulnerability scanning, static/dynamic code analysis, and penetration testing.Collaborate with development teams to integrate security into the development process (e.g., SAST/DAST integration, code reviews).
Develop and maintain security, hardening standards and guidelines for various systems and applications.Monitor and analyze security alerts and logs and respond to security incidents.Champion a DevSecOps culture by promoting security awareness and best practices across the organization.
Continuously research and evaluate new security technologies and tools.
Mentor and guide junior engineers on DevSecOps best practices.Participate in on-call rotation for production support.Contribute to the improvement of our overall security posture.