BlueShield Of California - El Dorado Hills, CA

posted 25 days ago

Full-time - Mid Level
El Dorado Hills, CA

About the position

As a DevSecOps Engineer in the IT Quality Engineering Organization, you will be responsible for ensuring the security and quality of software products. This role involves establishing best practices for DevSecOps methodologies, leading the implementation of these practices specifically for Azure, and collaborating with cross-functional teams to integrate security throughout the software development lifecycle. You will also provide training and mentoring to others in DevSecOps best practices, with a strong focus on cloud solutions and design.

Responsibilities

  • Evaluate and analyze the existing IT infrastructure, identifying areas for improvement and security enhancement.
  • Design and implement secure, scalable, and automated cloud-based solutions on Microsoft Azure to support application deployment and management.
  • Advocate for DevSecOps principles and practices within the organization.
  • Lead the implementation of DevSecOps practices, including continuous integration, continuous delivery, continuous testing (CI-CD-CT), and automated testing, tailored for the Azure cloud environment.
  • Collaborate with software development teams to integrate security controls and best practices into the application development process and to create robust testing strategies that cover functional, security, and performance aspects.
  • Develop and execute test plans, test cases, and test scripts to validate software functionality and security.
  • Encourage collaboration between development, operations, and security teams.
  • Maintain comprehensive documentation related to testing processes, security findings, and remediation efforts.
  • Generate reports on testing results, security assessments, and risk assessments.
  • Create automated test suites and pipelines.
  • Implement monitoring, logging, and alerting systems to ensure the security and availability of cloud-based infrastructure.
  • Integrate SonarQube with CI/CD pipelines and Azure DevOps.
  • Manage the configuration and infrastructure as code (IaC) using tools such as Terraform, Ansible, or similar, with a strong emphasis on security.
  • Conduct security assessments, vulnerability testing, and ensure compliance with industry standards and regulatory requirements.
  • Work closely with stakeholders to define and enforce security policies and access controls in the Azure environment.
  • Develop and maintain documentation for security processes, procedures, and configuration management.
  • Continuously improve testing methodologies and security processes.

Requirements

  • Bachelor's degree in computer science, Information Technology, or related field, or equivalent experience; Master's degree preferred.
  • Minimum 7 years of prior relevant experience in IT development and quality engineering.
  • 2 years of experience in DevSecOps field preferred.
  • 1 year of hands-on experience with cloud platforms and Infrastructure as code preferred.
  • Proven hands-on experience in cloud solutions and design for secure and compliant integration of applications on Microsoft Azure.
  • Solid understanding of DevSecOps principles.
  • Knowledge of healthcare industry standards including HIPAA and CMS regulations.
  • Experience with CI/CD pipelines, and automation tools like Jenkins, Ansible, Jira, GitLab CI, JFrog Artifactory, BitBucket, or Azure DevOps, with a focus on security integration and automated testing at all stages.
  • Strong knowledge of scripting languages (e.g., PowerShell, Bash, Python) for automation tasks, with an emphasis on security-related automation.
  • Experience in implementing and managing containerized applications using Docker and orchestration platforms like Kubernetes, with security considerations in mind.
  • Familiarity with infrastructure as code (IaC) concepts and tools such as Terraform or Ansible, with a focus on security best practices.
  • Expertise in cloud security best practices and their implementation within Azure environment.
  • Excellent problem-solving skills and ability to troubleshoot security-related issues.

Nice-to-haves

  • Preferred experience in leading digital transformation projects and cloud migration efforts with a strong focus on security.
  • Understanding of and experience with AIOps concepts and tools like Prometheus, Grafana, or ELK stack, and platforms like OpsRamp or DynaTrace, would be strongly preferred.
  • Experience with performance optimization as applied to cloud infrastructure and cloud application architectures.

Benefits

  • Competitive salary based on experience and location.
  • Opportunities for professional development and training.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service