Source description
About the role
Key Responsibilities
Own and manage:
CI/CD pipelines for secure and efficient deployments.
Infrastructure as Code (IaC) enforcement across environments.
Security tooling integration into development workflows.
Automated QA processes for vulnerability detection and compliance.
Change management evidence for audits and governance.
Conduct source code vulnerability checks and maintain a journal of exhibits for compliance.
Perform OWASP vulnerability checks and document findings.
Implement state-of-the-art analytics measures for proactive security monitoring.
Evaluate current business continuity measures, prioritize gaps, and implement updates.
Define and enforce multi-tenant security requirements.
Establish and maintain Disaster Recovery (DRS) measures with acceptable RTO/RPO targets.
Required Qualifications
7+ years of experience in DevSecOps, Platform Engineering, or related roles.
Strong expertise in CI/CD, IaC, and security automation.
Hands-on experience with SOC 2 Type II compliance and audit preparation.
Proficiency in vulnerability scanning tools and frameworks (e.g., OWASP).
Deep understanding of cloud security, multi-tenant architectures, and disaster recovery planning.
Excellent documentation and evidence management skills for compliance audits.
Preferred Skills
Familiarity with container security, Kubernetes, and microservices architecture.
Experience with automated QA frameworks and security analytics tools.
Strong scripting and automation skills (Python, Bash, etc.).
Certifications such as CISSP, AWS Security Specialty, or Certified DevSecOps Professional.
More at 3B Staffing