Senior DevSecOps Engineer
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe are seeking a Senior DevSecOps Engineer to join a Security Center of Excellence supporting a Global PC and Smart Devices Business. This is an exciting role where you will work with a global team of development engineers and security professionals, collaborating with multiple business units and DevOps teams to implement, configure, and administer DevSecOps tools in CI/CD pipelines.
You will stay up to date with the latest DevSecOps technology and trends while making a big impact within one of the largest PC organizations in the world. The ideal candidate takes initiative, has excellent organizational skills, and thrives in a fast-paced environment with multiple partners and projects.
- Implement, integrate, and maintain security tools in collaboration with your team and other business units
- Identify areas for improvement within CI/CD pipelines
- Research and recommend new tools, processes, and techniques
- Perform cybersecurity control and risk assessments of proposed and existing product and infrastructure architecture for compliance with internal requirements and international cloud security best practices
- Recommend technical, administrative, and physical remediations and mitigations for identified risks and vulnerabilities
- Leverage industry best practices and specialized expertise in application security to enhance internal security guidelines
- Ensure security guidelines are aligned with current industry standards and effectively address emerging threats
- Oversee the end-to-end design review process, utilizing findings from various security review quality gates
- Collaborate closely with other BUs' DevOps teams to assist in implementing and maintaining security tools and processes
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field
- Strong hands-on cybersecurity experience
- 3+ years of DevSecOps or Developer experience
- Knowledge of public cloud providers, especially AWS
- Background in implementing and maintaining DevSecOps tools
- Understanding of secure software development lifecycle (SDLC), threat modeling, and risk assessment
- Proficiency in security testing tools and methodologies (e.g., SAST, DAST, SCA)
- Familiarity with modern development frameworks and application security
- Strong written and verbal communication and interpersonal skills
- Capability to work independently as well as function as an integral part of a team, taking initiative and ownership in a fast-paced environment
- Flexibility to work across regions and functions to solve problems and get things done
- Fluency in English (C1 level)
- Expertise in Black Duck Coverity, Checkmarx ZAP, and/or Fuzz Testing
- Skills in JFrog Artifactory, Jenkins, and Snyk
- Competency in Wiz CSPM
