DevSecOps Engineer

$97,000 - $154,000/Yr

Sumitomo Mitsui Financial Group - White Plains, NY

posted about 2 months ago

Full-time - Mid Level
Remote - White Plains, NY
10,001+ employees
Credit Intermediation and Related Activities

About the position

SMBC Group is a top-tier global financial group with a rich 400-year history, headquartered in Tokyo. The group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance, with over 130 offices and 80,000 employees worldwide across nearly 40 countries. The role of DevSecOps Engineer is crucial in safeguarding Capital Market's information systems through the administration of security projects. This position requires active participation in technical research and development of both on-premises and cloud solutions, aimed at fostering continuous innovation within the Cyber Security and Information Risk department. As a DevSecOps Engineer Associate, you will act as a liaison between Development, Operations, and Cybersecurity Risk teams, utilizing a blend of programming knowledge, threat management, and communication skills to automate and integrate cybersecurity measures throughout the Software Development Life Cycle (SDLC). You will report directly to the Head of Cyber Security of Capital Markets, with additional reporting lines to the regional Chief Information Security Officer (CISO) of the Americas Division and the Capital Markets' Chief Operating Officer (COO). Your primary responsibilities will include ensuring that Information Security systems and cloud services are configured, deployed, and maintained in accordance with SMBC's policies and standards. You will collaborate closely with the DevOps team to ensure that critical components of the Continuous Integration/Continuous Deployment (CI/CD) pipeline are configured according to existing policies and procedures, ensuring that security is integrated into the pipeline. This role also involves ongoing technical research and development to support continuous innovation in Cyber Security and Information Risk management.

Responsibilities

  • Administer security projects to safeguard Capital Market's information systems.
  • Participate in technical research and development of on-prem and cloud solutions for Cyber Security.
  • Act as a liaison between Development, Operations, and Cybersecurity Risk teams.
  • Automate and integrate cybersecurity at every stage of the SDLC lifecycle.
  • Ensure Information Security systems and cloud services are configured and maintained according to policies and standards.
  • Collaborate with the DevOps team to configure CI/CD pipeline components according to security policies.
  • Scan and track remediation of vulnerabilities in code, containers, and infrastructure as code.
  • Implement automation for security compliance testing in the development lifecycle.
  • Develop and report Key Risk Indicators (KRIs) within the SSDLC processes.
  • Create and present updates to management regarding project accomplishments, challenges, and risks.

Requirements

  • 4+ years of hands-on security engineer and operations experience securing cloud environments and developing automation workflows.
  • Practical experience in implementing security checks within a Secure SDLC Pipeline.
  • Hands-on experience with CI/CD tools such as Jenkins, Git, Github Actions, Artifactory, etc.
  • Hands-on experience with Secrets Management, SCA, and open-source tools.
  • Scripting experience with one or more scripting languages: bash, python, perl, YAML - required.
  • Hands-on experience with infrastructure as code tools such as Terraform or CloudFormation - required.
  • Familiarity with container orchestration technologies such as Kubernetes, Openshift, EKS, AKS.
  • Experience with container image scanning and vulnerability management.
  • AWS or Azure Certifications.

Benefits

  • Competitive salary range between $97,000.00 and $154,000.00 based on qualifications and experience.
  • Eligibility for an annual discretionary incentive award.
  • Comprehensive benefits portfolio offered to employees.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service