Pennsylvania State University - State College, PA

posted 4 months ago

Full-time - Mid Level
State College, PA
Educational Services

About the position

The DevSecOps Research and Development Engineer at Penn State is responsible for integrating security practices into the DevOps process. This role involves collaborating with cross-functional teams to design, implement, and maintain secure software development pipelines. The engineer will work on automating security testing and compliance checks, ensuring that security is embedded throughout the software development lifecycle. The position requires a strong understanding of both development and security principles, as well as the ability to communicate effectively with both technical and non-technical stakeholders. In this role, the engineer will also be tasked with researching and evaluating new security tools and technologies, providing recommendations for their integration into existing systems. The engineer will participate in threat modeling and risk assessment activities, helping to identify potential vulnerabilities and develop mitigation strategies. Additionally, the engineer will contribute to the development of security policies and best practices, ensuring that the organization adheres to industry standards and regulations. The ideal candidate will have a passion for security and a desire to stay current with emerging threats and technologies. They will be expected to contribute to a culture of security awareness within the organization, providing training and support to other team members as needed. This position offers an exciting opportunity to work on cutting-edge security initiatives in a collaborative and innovative environment.

Responsibilities

  • Integrate security practices into the DevOps process.
  • Collaborate with cross-functional teams to design and implement secure software development pipelines.
  • Automate security testing and compliance checks.
  • Research and evaluate new security tools and technologies.
  • Participate in threat modeling and risk assessment activities.
  • Contribute to the development of security policies and best practices.
  • Provide training and support to team members on security awareness.

Requirements

  • Strong understanding of DevOps principles and practices.
  • Experience with security tools and technologies.
  • Knowledge of software development lifecycle and security best practices.
  • Ability to communicate effectively with technical and non-technical stakeholders.
  • Experience with threat modeling and risk assessment.

Nice-to-haves

  • Familiarity with cloud security practices.
  • Experience with container security.
  • Knowledge of compliance frameworks such as NIST or ISO.
  • Certifications in security (e.g., CISSP, CISM, or similar).

Benefits

  • Health insurance coverage.
  • Retirement savings plan with employer matching.
  • Paid time off and holidays.
  • Professional development opportunities.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service