עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
STARTICA is looking for a Senior DevSecOps Engineer.
As a DevSecOps Engineer, you will be responsible for integrating security practices within the DevOps processes, ensuring that the software development lifecycle (SSDLC) incorporates robust security measures from the start. You will work closely with development, operations, and security teams to automate security processes, monitor and respond to security threats, and enforce compliance with security policies.
! This is a part-time job, 2-3 days a week.
Key Responsibilities:
- Security Integration:
- Integrate security controls, tools, and processes into the CI/CD pipeline.
- Collaborate with developers to ensure secure coding practices.
- Automate security testing within the CI/CD pipeline (e.g., SAST, DAST, IAST).
- Monitoring & Incident Response:
- Implement continuous monitoring tools to detect security threats and vulnerabilities.
- Work with the security team to develop and implement incident response procedures.
- Analyze and respond to security incidents in a timely manner.
- Compliance & Risk Management:
- Ensure that the DevOps processes comply with industry standards and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS).
- Perform regular security risk assessments and audits to identify vulnerabilities and weaknesses.
- Provide recommendations and enforce policies to mitigate risks.
- Tooling & Automation:
- Develop and maintain security automation scripts and tools.
- Manage and integrate security tools (e.g., SIEM, vulnerability scanners) into the DevOps pipeline.
- Automate infrastructure security (e.g., IAM, firewalls) using Infrastructure as Code (IaC).
- Collaboration & Training:
- Work closely with development and operations teams to ensure security is a shared responsibility.
- Provide training and awareness programs for development and operations teams on security best practices.
- Stay updated on the latest security trends and technologies, and apply this knowledge to improve security posture.
- Cloud Security:
- Manage cloud security posture and ensure data protection in cloud services.
- Secure containerized environments (e.g., Docker, Kubernetes).
Who we are looking for:
- Technical Skills:
- Strong understanding with encryption/decryption methodologies, tools and processes (KMS, HSM etc.)
- Proficient in CI/CD tools (e.g., Jenkins, GitLab CI, CircleCI) .
- Experience with security tools like SAST (e.g., SonarQube, coverity), DAST (e.g., OWASP ZAP), and IAST and vulnerabilities tools(e.g. blackduck).
- Familiarity with configuration management tools (e.g., Ansible, Puppet, Chef).
- Knowledge of containerization and orchestration (Docker, Kubernetes).
- Experience with scripting and automation (e.g., Python, Bash, PowerShell).
- Must have Experience with thales
- Soft Skills:
- Strong problem-solving skills and the ability to think like an attacker.
- Excellent communication and collaboration skills.
- Ability to work in a fast-paced, dynamic environment.
- Strong attention to detail and organizational skills.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
ירושלים
בוקר