Search jobs > Durham, NC > Security engineer

Security Engineer (Application Security, DevSecOps)

NetApp
Research Triangle Park, NC, US
Full-time

Title : Security Engineer (Application Security, DevSecOps)

Location :

Bangalore, Karnataka, IN, 560071

Requisition ID : 127561

Job Summary

This role involves collaborating with different teams to develop and maintain secure cloud architectures in line with best practices.

It includes setting up continuous asset monitoring, administering security controls across cloud infrastructure, and implementing secure practices in development lifecycle and containerization platforms.

The role also requires developing automated security tools for integration into the CI / CD pipeline, conducting regular security testing and vulnerability scanning, and assessing data flows for potential security risks.

Furthermore, the role involves providing guidance to other teams, managing vulnerability resolution, and participating in incident response efforts.

Understanding of secure software development practices and DevSecOps methodologies.

Job Requirements

  • Experience in security engineering and DevSecOps.
  • Lead and oversee all aspects of the Secure Software Development Lifecycle.
  • Implement and manage security tools within the CI / CD pipeline, focusing on DevSecOps practices.
  • Conduct threat modeling, design, and architectural reviews to identify potential risks.
  • Support third-party penetration testing by analyzing vulnerabilities and assessing their potential impact and exploitability.
  • Possess a foundational understanding of web application security.
  • Demonstrate strong knowledge of cloud computing platforms like AWS, Azure, GCP and their associated security services and features.
  • Experience with SAST, SCA, and DAST, with the ability to address real-world challenges in these areas.
  • Understand runtime security, image scanning, network security, access control, host OS hardening, and vulnerability management in the container lifecycle.
  • Knowledgeable in Kubernetes and the implementation of best practices.
  • Proven expertise in using Terraform and other infrastructure as code tools, managing vulnerabilities, policies and implementing best practices.
  • Handle vulnerability management for images.
  • Adaptable and capable of exploring various products with a wide range of tools and pipelines.
  • Familiarity with CI / CD tools such as GitHub Actions, Jenkins or TeamCity.
  • Stay informed about emerging security threats and technologies, offering recommendations for security enhancements.
  • Experience in automating security controls.
  • Understanding of networking and communication protocols like TCP / IP, UDP, SSL / TLS, IPSEC, HTTP, HTTPS, BGP.
  • Proficiency in scripting or programming languages like Python, Gol, Ruby for security automation and integration.

Education

  • Required 4 years of experience in the security domain.
  • Bachelor's degree in computer science, Information Security, or a related field.

Job Segment : Cloud, Testing, Application Engineering, Computer Science, Information Security, Technology, Engineering

4 days ago
Related jobs
Promoted
VirtualVocations
Raleigh, North Carolina

A company is looking for an Application Security Engineer to enhance the security of their software applications. ...

Promoted
MITRE
Raleigh, North Carolina

MS in electrical engineering, computer engineering, applied mathematics, physics, systems engineering, or related discipline. Applicants selected for this position will be subject to a government security investigation and must meet eligibility requirements for access to classified information or ap...

Promoted
VirtualVocations
Raleigh, North Carolina

A company is looking for a Staff Software Engineer, DevOps and Security. Terraform, CloudFormation) and CI/CD pipelinesStrong understanding of security best practices and compliance requirements (e. SOC 2, GDPR)Experience implementing and managing security tools for vulnerability scanning and secret...

SAS
Cary, North Carolina

Review application architecture, identify security gaps, and help improve the security posture of business-critical multi-tier applications in legacy, hybrid cloud, and public cloud environments with refactoring and promotions between the environments. Application Security Architect- Remote or Hybri...

Promoted
VirtualVocations
Raleigh, North Carolina

A company is looking for a Security Engineer, Threat Detection. ...

Zachary Piper
Raleigh, North Carolina

Network Engineer must possess a Top Secret Security Clearance with SCI eligibility and must work onsite. Network Engineer in the Herndon, VA area for an exciting opportunity with a premier global technology organization. Network Engineer (Top Secret Clearance) include:. Work with a variety of engine...

Cisco
Durham, North Carolina

Cisco Security Customer Experience (CX) organization supports customers through the entire lifecycle of a security solution: from understanding business needs to deploying custom solutions, from optimizing existing solutions to developing applications that meets specific needs; from helping customer...

Deutsche Bank
Cary, North Carolina

Family and Medical Leave Act ; Employee Polygraph Protection Act and Pay Transparency Nondiscrimination Provision ....

Cisco
Durham, North Carolina

Enterprise IT Security team is changing the way we run Cisco’s operations by improving the power of technology, the best of business processes. We are partners with CISO organization on vision, strategy and execution that continues to improve our security posture and reduce agreed risk. Work closely...

Vaco
Raleigh, North Carolina

The Senior IT Security Engineer will be responsible for the operational ownership of various IT security infrastructures such as Proxy, SIEM, EDR, Firewalls, Email-filter, VPN, etc. We are actively seeking a Senior IT Security Engineer on behalf of our Ag Tech client. The ideal candidate will have e...