Cloud DevSecOps/InfoSec

Job ID: 37365017

Budget: $2 – $8 USD

Team is looking for a Security/DevSecOps Engineer to help secure web application and infrastructure initiatives. You will use your talents to help secure our application by coordinating and architecting security controls, performing security reviews, and testing controls. As a Security/DevSecOps Engineer you will be responsible for conducting security architecture reviews for full stack applications built on cloud technologies . You will conduct manual application security tests and audit source code to support releases and act as a crucial bridge between development and security, ensuring that software is built and deployed securely without compromising agility and speed. You'll work to identify security testing plans and conduct testing to ensure security controls are in place and implemented correctly. Development of tooling to support security improvement initiatives for the platform and provide security guidance for new projects, features, and changes to projects.

Skills and Experience:

- Strong knowledge and experience in AWS cloud platform
- Expertise in implementing cloud security measures and best practices
- Proficient in managing and securing cloud infrastructure
- Familiarity with security compliance frameworks and regulations
- Ability to identify and mitigate security risks in the cloud environment
- Experience in setting up and managing user access and permissions
- Knowledge of encryption, network security, and identity and access management (IAM)
- Strong communication and collaboration skills to work closely with the client's team
- Ability to provide regular updates and reports on security measures and improvements.
- Web Application Security and Penetration Testing of complex enterprise environments
- Hands-on experience with manual and tool assisted Source Code Security Review
- Experience securing Cloud Environments for large enterprise applications
- Background in web application development and/or code auditing
- Strong verbal & written communication skills and the ability to succinctly communicate security concerns at various technical levels
- Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Ethical Hacker (CEH) are a plus.