FICO

posted 26 days ago

Full-time - Principal
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

About the position

As a Principal Engineer at FICO, you will play a crucial role in establishing secure foundations for a new product development DevOps pipeline. This position involves collaborating with software development teams to address security challenges and technical debt, while also working closely with security engineers and architects to define necessary security architecture and design requirements. Your expertise in modern CI/CD systems will be essential in implementing secure infrastructure and policy-as-code, as well as participating in threat modeling exercises.

Responsibilities

  • Collaborate between Cybersecurity, DevOps, and Development teams to achieve alignment between security and business objectives.
  • Construct contextual security requirements for vendor tools and integrated systems.
  • Develop vendor tool secure onboarding guidance for system administrators and users.
  • Design and implement AWS based solutions using Terraform for automated Health Checks for security posture validation.
  • Actively participate in security review and threat modeling exercises to identify risks.
  • Provide technical guidance to development teams on security best practices, security architecture, and security controls.
  • Integrate Application and DevOps processes with CI/CD pipelines of the software development lifecycle.
  • Build CI/CD pipelines with Jenkins MPL and GitHub Actions for Security Artifacts.
  • Leverage orchestration systems including Docker and Kubernetes to deliver security services.
  • Integrate software service tools (Jenkins, jFrog Artifactory) into automation for security services.
  • Evaluate and on-board security tools and/or scanners into the Security DevOps lifecycle for multiple tech stacks.
  • Remediate code- and dependency-level security findings in partnership with product development teams.
  • Introduce and enhance Continuous Monitoring (Cloud Architecture, App Performance and Logs) for security services.
  • Evaluate the stability, compatibility, scalability, interoperability, and performance of software products.
  • Contribute feature enhancements to internally developed Cybersecurity tools.
  • Integrate Cybersecurity tools into the Security DevOps pipelines.
  • Drive continuous improvement to both the Security DevOps pipelines, and to the Cybersecurity tools, services, and processes.
  • Create and share practical demonstrations of proposed solutions.
  • Mentor and train other engineers and support knowledge sharing.
  • Drive technical discussions and serve as a source of technical expertise.

Requirements

  • Strong knowledge of programming, architecture, CI/CD, and automation.
  • Solid experience with AWS API, EKS, and Terraform.
  • Strong understanding and hands-on experience building CI/CD ecosystems to meet the demands of agile and secure development.
  • Extensive architectural understanding of cloud security, Kubernetes, cloud-native computing, and microservices.
  • Demonstrated ability to evaluate complex projects and clearly articulate secure design requirements, applying a 'security mindset' and best-practices quality-first approach.
  • Direct experience standing up and securely administering instances of ArgoCD, Crossplane, Akuity, Upbound Spaces, and Solo.io strongly preferred.
  • Developer-level experience with Java and Golang strongly preferred.
  • Direct experience standing up and securely administering instances of Artifactory, Backstage, Buf, and MongoDB preferred.
  • Experience working within one or more compliance frameworks (PCI 4, SOC 2, ISO 27001) is a plus.
  • Knowledge of Security Tools (DAST, SAST, SCA, IAST, IaC, etc.) is a plus.
  • Experience leading or participating in threat modeling, penetration testing, and security reviews is a plus.
  • Bachelor/Master's degree in computer science or related discipline, or relevant experience in software design, development, testing, and deployment.

Nice-to-haves

  • Experience working within one or more compliance frameworks (PCI 4, SOC 2, ISO 27001) is a plus.
  • Knowledge of Security Tools (DAST, SAST, SCA, IAST, IaC, etc.) is a plus.
  • Experience leading or participating in threat modeling, penetration testing, and security reviews is a plus.

Benefits

  • Highly competitive compensation, benefits and rewards programs that encourage you to bring your best every day and be recognized for doing so.
  • An engaging, people-first work environment offering work/life balance, employee resource groups, and social events to promote interaction and camaraderie.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service