Yardi Systems - Tustin, CA

posted about 2 months ago

Full-time
Tustin, CA
Publishing Industries

About the position

The Development Security Operations Analyst will play a crucial role in integrating security practices into our development and operations processes. This position will work closely with the development, operations, and security teams to ensure the continuous integration and continuous delivery (CI/CD) pipelines are secure, efficient, and compliant with industry standards and best practices. The ideal candidate will have a rich background in designing and implementing secure coding practices, understanding threats, and developing strategies to mitigate potential risks. In this role, the analyst will embed security controls and practices into the CI/CD pipeline, collaborating with development teams to integrate security tools and processes into the development lifecycle. It is essential that security is considered at every stage of the software development process, from design to deployment. The analyst will conduct regular security assessments and vulnerability scans of applications and infrastructure, monitor and address security vulnerabilities, and implement automated security testing tools and processes. Additionally, the analyst will assist in the development and execution of incident response plans, investigate and respond to security incidents and breaches, and perform root cause analysis while recommending corrective actions. Compliance with relevant security standards and regulations such as ISO 27001, NIST, and GDPR is critical, as is staying up-to-date with the latest security trends, threats, and technologies. The analyst will advocate for and implement security best practices across development and operations teams, working closely with cross-functional teams to promote a security-first culture and providing security training and awareness programs for development and operations teams.

Responsibilities

  • Embed security controls and practices into the CI/CD pipeline.
  • Collaborate with development teams to integrate security tools and processes into the development lifecycle.
  • Ensure that security is considered at every stage of the software development process, from design to deployment.
  • Conduct regular security assessments and vulnerability scans of applications and infrastructure.
  • Monitor and address security vulnerabilities in applications and systems.
  • Implement automated security testing tools and processes.
  • Assist in the development and execution of incident response plans.
  • Investigate and respond to security incidents and breaches.
  • Perform root cause analysis and recommend corrective actions.
  • Ensure compliance with relevant security standards and regulations (e.g., ISO 27001, NIST, GDPR).
  • Stay up-to-date with the latest security trends, threats, and technologies.
  • Advocate for and implement security best practices across development and operations teams.
  • Work closely with cross-functional teams to promote a security-first culture.
  • Provide security training and awareness programs for development and operations teams.
  • Communicate security risks and recommendations to stakeholders and management.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • At least 3 years of experience in a similar role.
  • Proficiency in security tools and technologies (e.g., static code analysis, dynamic application security testing, vulnerability scanners).
  • Experience with CI/CD tools (e.g., Jenkins, GitLab CI, CircleCI).
  • Knowledge of cloud security (e.g., AWS, Azure, Google Cloud) and container security (e.g., Docker, Kubernetes).
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work collaboratively in a fast-paced environment.

Nice-to-haves

  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or GIAC certifications.
  • Experience with infrastructure as code (IaC) tools (e.g., Terraform, Ansible).
  • Familiarity with compliance frameworks and standards.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service