DevSecOps Engineer
Santa Clara, California
We are seeking a skilled and experienced DevSecOps Engineer with a strong focus on DevOps to join our dynamic team. In this role, you will be responsible for integrating security practices into our DevOps processes, ensuring that our software development lifecycle (SDLC) is secure, efficient, and scalable..
Job description:
- Be the DevSecOps and DevOps owner for Projects
- US citizen/Green Card holder is a requirement.
- Previous experience working on Fedramp certified application is an added advantage.
- Collaborate between development and operations teams to streamline software delivery.
- Integrate security practices into the DevOps process to ensure secure and resilient software delivery.
- Make software development and delivery faster, efficient, secure and resilient with a focus on continuous security.
- Automate development, testing, deployment process along with security testing, vulnerability scanning, compliance checks
- Participate in incident response activities, helping to investigate and mitigate security incidents in a timely manner.
- Use CI/CD tools, configuration management, monitoring tools, infrastructure as code (IaC) for Software delivery and Integrate Code Security Tools and Practices (ex. SAST, DAST, SCA, Security Frameworks) to shift security left
- Create hermetic builds using Bazel
- Work with product managers, developers, and quality engineers in cross-functional teams to provide feedback.
- Communicate progress in an agile environment with team members spread across multiple geographies.
Job Requirements:
- Minimum of 4 years of proven experience in a DevSecOps role with a strong DevOps background.
- Strong understanding of DevSecOps and DevOps principles and practices
- Strong experience with Git Version Control
- Extensive experience with CICD pipeline automation and tools (ex. Bitbucket, GitHub Actions, Azure DevOps, AWS codePipeline)
- Experience with Bazel to create hermetic builds
- Strong understanding of cybersecurity principles, threats, and vulnerabilities
- Experience with Code Security Tools and Practices (ex. SAST, DAST, SCA, Security Frameworks)
- Familiarity with cybersecurity frameworks, regulations, and compliance standards (e.g., NIST, HIPAA, PCI-DSS)
- Knowledge of security technologies and tools (e.g., firewalls, IDS/IPS, encryption)
- Knowledge of Python and Bash scripting
- Infrastructure as Code (ex. Terraform, Cloud Formation, CDK,etc.)
- Strong communication skills to articulate technical concepts to non-technical stakeholders
- Strong collaboration skills to work effectively with cross-functional teams
Good to have:
- Strong understanding of software supply chain risks, threats, and vulnerabilities
- Familiarity with software supply security standards, frameworks, and regulations (e.g., SBOM, SLSA, NIST 800-161)
- Experience with integrating security into the software development life cycle
- Knowledge of secure coding practices, code reviews, and security testing methodologies
Qualifications
- Graduate degree in Computer science or equivalent. Masters an added advantage.
Lineaje Website Link: https://www.lineaje.com/