This is an exciting opportunity to work with a public sector organisation for a Senior Security Engineer with experience working with DevOps/DevSecOps teams.
Responsibilities:
- Develop cyber security standards to govern the implementation of systems and software.
- Work with internal cyber teams to identify and implement capability needed to support DevSecOps pipelines such as policy as code, continuous compliance, integrated risk process, dynamic evidence collection and reporting.
- Conducting threat modelling exercises to understand a products threat landscape, processing this information into relevant DevSecOps security mitigations.
- Prioritising and managing Cyber risk, providing teams with actionable recommendations for mitigating and minimising threats in their environment.
- Perform detailed maturity assessments of operational and software development teams, identifying gaps and creating remediation plans to iterate towards high performance and compliance.
- Develop and maintain application security tooling, providing support for adoption and integration with existing CI/CD pipelines, reporting tools, and assurance platforms.
- Provide expert implementation advice for cloud environments, continuous integration and continuous deployment pipelines, with a focus on building security into every stage of a products lifecycle.
Requirements:
- 3 years' experience working with DevOps teams or Software Development teams, implementing secure by design principles and automated security testing capabilities.
- Strong Experience building CI/CD pipelines, experience with Azure DevOps and AWS Code Suite.
- Strong communication skills capable of building relationships and influencing outcomes across technical and business stakeholders.
- Experience developing security controls across cloud, infrastructure, applications, networks and endpoints.
- Baseline/NV1 clearance required
If you meet the above requirements and are interested in this role, please apply with your resume! You can contact Urvi Thacker for any queries.
