Description:
Digital Graphiks is seeking a skilled DevSecOps Engineer to join our dynamic team.
Responsibilities:
- Develop, implement, and maintain security measures for software development lifecycle (SDLC), including secure coding practices, security testing, and deployment processes.
- Collaborate with cross-functional teams to integrate security controls, threat modeling, and risk assessments into the CI/CD pipeline.
- Implement and manage security tools, automation, and continuous monitoring solutions to identify and mitigate vulnerabilities across applications and infrastructure.
- Evaluate, select, and deploy appropriate tools and technologies to support secure development and deployment practices.
- Conduct security assessments, including penetration testing, code reviews, and security audits, and provide recommendations to address identified issues.
- Establish and maintain security policies, standards, and best practices in alignment with industry standards and compliance requirements.
- Support incident response and participate in remediation efforts for security-related issues.
Requirements:
- Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent experience).
- Proven experience in DevOps practices and methodologies, including continuous integration, continuous deployment, and automation tools (e.g., Jenkins, Git, Docker, Kubernetes).
- Solid understanding of cybersecurity principles and best practices with experience in security architectures, firewalls, intrusion detection systems, and vulnerability management.
- Proficiency in scripting and programming languages (e.g., Python, Bash, Ruby, or similar).
- Experience with security tools such as static/dynamic application security testing (SAST/DAST), container security, and vulnerability scanning.
- Familiarity with cloud platforms (AWS, Azure, GCP) and their security features.
Preferred Qualifications:
- Certifications in relevant areas such as CISSP, CEH, Security+, or similar.
- Experience in secure software development and familiarity with secure SDLC methodologies.
- Knowledge of regulatory compliance standards such as GDPR, HIPAA, or others.