Principal Engineer -DevSecOps

$145,600 - $156,000/Yr

Randstad - Hollywood, FL

posted about 2 months ago

Full-time - Principal
Hollywood, FL
Administrative and Support Services

About the position

As a Principal DevSecOps Engineer, you will play a pivotal role in shaping our software development lifecycle by integrating security practices seamlessly into our processes. Your technical expertise and leadership will drive the implementation of robust CICD (Continuous Integration and Continuous Deployment) patterns while adhering to industry standards and policies. You'll collaborate with cross-functional teams, ensuring that our applications are secure, reliable, and efficiently deployed. In this role, you will design and implement secure, scalable solutions to address infrastructure and security requirements. You will champion DevSecOps practices, integrating security seamlessly into the SDLC with tools like SAST/DAST solutions and Infrastructure as Code (IaC) scanning (e.g., Prisma Cloud, SonarQube). Your responsibilities will include identifying and implementing opportunities for pipeline automation and optimization, driving efficiency and speed. You will embrace Infrastructure as Code (IaC) using tools like Terraform and Kubernetes to automate and manage multi-cloud deployments (e.g.: AWS, Azure). You will lead the containerization charge, leveraging Docker and Helm 3 for efficient application packaging and deployment. A strong understanding of security concepts, including threat modeling, risk assessment, and vulnerability management, is essential. You will also implement state-of-the-art artifact management solutions for secure storage and distribution (e.g., Artifactory, Nexus) and maintain robust monitoring solutions (e.g., Prometheus, Grafana) to gain deep insights into application and infrastructure health. Your role will require you to integrate and leverage a SIEM tool (Splunk or similar) to collect, analyze, and correlate security-related data from various sources for advanced threat detection and incident response. You will foster a collaborative environment, working closely with development, security, and operations teams to ensure seamless software delivery. Staying ahead of the curve by researching and integrating the latest DevSecOps trends and methodologies will be crucial, as will sharing your expertise through internal training and knowledge sharing sessions. You will also be responsible for developing and maintaining clear documentation for DevSecOps processes and tools, ensuring consistency and knowledge transfer, troubleshooting and resolving complex issues within the CI/CD pipeline and cloud deployments, and keeping incident tracking tools updated. A proactive approach to identify and mitigate security risks is essential, as is championing agile methodologies within the DevSecOps workflow, ensuring continuous integration, delivery, and feedback loops. This position requires a Bachelor's degree in Computer Science or Information Technology and at least 9 years of experience in DevSecOps principles and practices. You will need a proven track record of designing and implementing secure, automated CI/CD pipelines with modern tools, a deep understanding of Infrastructure as Code (IaC) tools, and familiarity with cloud technologies for cloud DevSecOps.

Responsibilities

  • Design and implement secure, scalable solutions to address infrastructure and security requirements.
  • Champion DevSecOps practices, integrating security seamlessly into the SDLC with tools like SAST/DAST solutions and Infrastructure as Code (IaC) scanning (e.g., Prisma Cloud, SonarQube).
  • Identify and implement opportunities for pipeline automation and optimization, driving efficiency and speed.
  • Embrace Infrastructure as Code (IaC) using tools like Terraform and Kubernetes to automate and manage multi-cloud deployments (e.g.: AWS, Azure).
  • Lead the containerization charge, leveraging Docker and Helm 3 for efficient application packaging and deployment.
  • Implement state-of-the-art artifact management solutions for secure storage and distribution (e.g., Artifactory, Nexus).
  • Implement and maintain robust monitoring solutions (e.g., Prometheus, Grafana) to gain deep insights into application and infrastructure health.
  • Integrate and leverage a SIEM tool (Splunk or similar) to collect, analyze, and correlate security-related data from various sources for advanced threat detection and incident response.
  • Foster a collaborative environment, working closely with development, security, and operations teams to ensure seamless software delivery.
  • Stay ahead of the curve by researching and integrating the latest DevSecOps trends and methodologies.
  • Share your expertise through internal training and knowledge sharing sessions.
  • Develop and maintain clear documentation for DevSecOps processes and tools, ensuring consistency and knowledge transfer.
  • Troubleshoot and resolve complex issues within the CI/CD pipeline and cloud deployments.
  • Keep incident tracking tools updated and document discoveries and concerns.
  • Proactively identify and mitigate security risks.
  • Champion agile methodologies within the DevSecOps workflow, ensuring continuous integration, delivery, and feedback loops.

Requirements

  • Bachelor's degree in Computer Science or Information Technology field.
  • 9+ years of experience in DevSecOps principles and practices.
  • Proven track record of designing and implementing secure, automated CI/CD pipelines with modern tools (GitOps, GitHub Actions, etc.).
  • Deep understanding of Infrastructure as Code (IaC) tools (Terraform, Kubernetes) and multi-cloud environments (AWS, Azure, Google Cloud Platform).
  • Deep understanding of containerization technologies (Docker, Helm 3).
  • Experience with next-generation artifact management solutions (Artifactory, JFrog).
  • Experience integrating security best practices and tools (SAST/DAST, IaC scanning) into the SDLC.
  • Familiarity with API Security, Container Security, and AWS Cloud Security.
  • Knowledge of Prisma Cloud, SIEM, SOC, Nessus, CrowdStrike, or similar services.
  • Excellent communication, collaboration, and problem-solving skills.
  • Ability to thrive in a fast-paced, dynamic environment.
  • Strong scripting skills (Python, Go, Bash).

Nice-to-haves

  • Possess expert level industry certification(s) in Azure.

Benefits

  • Comprehensive benefits package including health insurance, an incentive and recognition program, and 401K contribution.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service