Sr. DevSecOps Engineer
Sr. DevSecOps Engineer
Our client is an exceptional 100-person (and growing) technology company with an established track record of success and consistent year-over-year growth trajectory of 50%+ servicing the automotive industry. Its core product – a premier customer relationship platform – has won a number of awards and is widely recognized for being the innovation leader among its peers.
You are someone who is tired of not being challenged, of not having a voice and of working with outdated technologies. In your current organization you stand out among your peers as a driver and an innovative thinker. You want to be a direct contributor to a dynamic team that enjoys solving difficult problems together every day and where everyone truly appreciates what you bring to the 100% virtual table.
Role Expectations:
- Document and maintain security policies that span infrastructure, software development practices, security incident management, and safe practices for all employees.
- Audit security compliance on an adhoc and recurring basis.
- Implement security training for employees on an annual basis and during new hire onboarding.
- Provide technical security training and advise engineering teams on preventative security practices that include infrastructure, code, access controls, etc.
- Coordinate penetration testing through an independent 3rd party and provide internal penetration testing more frequently as need.
- Coordinate penetration testing with a 3rd party at least annually.
- Establish, maintain, investigate, and resolve security alerts.
- Implement security improvements, individually and by guiding other teams.
- Participate in meetings with internal teams, legal, vendors, and customers as a security expert.
- Answer written and verbal inquiries from vendors and customers about security practices
- Support development teams and QA with the processes, documentation, tools, and guidance to effectively deliver software.
- Develop, optimize, and troubleshoot build pipelines managed in Jenkins.
- Develop, optimize, and troubleshoot deployment pipelines managed in Octopus.
- Identify and resolve performance, stability, and scalability issues with build, test, and deployment pipelines.
- Setup and maintain development and testing environments.
- Develop tools in .NET Core to auto-create fully functional environments on-demand for testing in isolation.
- Support development teams by creating and configuring AWS assets via Terraform.
- Participate in releases during business and non-business hours.
- Develop metrics, monitoring, and alerting to observe the health of the build, test, and deployment systems.
- Be proactive in anticipating issues and take corrective action to prevent them.
- Promptly resolve CI/CD issues to unblock development and QA teams.
Required Skills:
- Demonstrate senior-level expertise in most of the following technologies: Jenkins, Octopus, Terraform, AWS, C# .NET, Web APIs, and IIS/Kestrel.
- A proven history of developing and managing performant, scalable, and durable CI/CD pipelines.
- Hands-on experience building and deploying complex applications in a production environment.
- Working knowledge of DevOps best practices and tools.
- A data-driven approach to problem solving and communications.
- Ability to balance urgency with sound decision making and careful execution.
- Ability to balance business and technical objectives when making decisions.
- Ability to balance multiple assignments in a fast-paced environment.
- Exceptional communication, problem solving, and analytical skills is a must.
- Have a positive, can-do, user-centered attitude.
Nice to have:
- Experience establishing a written security strategy
- Comfort with setting security guidelines and auditing them for compliance
- Experience building and maintaining escalation systems
Benefits:
- Competitive salary
- Profit sharing plan
- Health, Vision, and Dental Insurance (eligible on day 1)
- 401K with matching up to 4%
- 9 company holidays + 15 vacation days in first year
- Ample professional growth opportunities
- Pluralsight subscription
Please Note: You must be a US citizen or eligible to work in the United States for this position.