As a member of the Security & Infrastructure Operations team this senior level IT Security will support the team by leading major security initiatives implementations and integrations. Additionally the resource will drive application and infrastructure security within multiple platforms to minimize application vulnerabilities and application risk:
Security Integration:Integrate security as an integral part of the CI/CD pipeline automating security testing and scanning processes.
Vulnerability Management:Identify assess and manage security vulnerabilities throughout the SDLC.
Security Automation:Implement and maintain security automation tools and scripts to streamline security processes.
Threat Modeling and Risk Assessment:Conduct threat modeling and risk assessments to identify potential security vulnerabilities.
Security Policy and Compliance:Enforce security policies and ensure compliance with agency policies and relevant regulations and standards.
Collaboration:Work closely with other IT teams and stakeholders to ensure security best practices are followed.
Incident Response:Participate in security incident response and recovery efforts.
Continuous Improvement:Continuously improve security practices and tools based on industry best practices and emerging threats.
Documentation:Document security processes procedures and findings.
Questions: 4 Year College Degree (Required) 4 Years Proficiency with Security scanning & vulnerability management tools (Qualys Checkmarx AutoRabit CodeScan) (Required) 4 years Proficiency with DevOps platforms (Azure DevOps Copado) (Required) 4 years Proficiency with Operating Systems (Windows/Linux) (Required) 4 years Administering Security Controls & Management Cloud Computing Platforms (Salesforce) (Required) 4 years Working knowledge of Security Frameworks & Standards (OWASP Top 10 SANS 25 NIST SP 80053 etc. (Required) 4 years Working knowledge of Web Application Security tools (F5 Web Application Firewall Cloudfare AppOmni) (Required) 4 years Working knowledge of SIEM/SOAR tools (Chronicle Splunk) (Required) 4 years Working knowledge of Integration platforms (ServiceNow MuleSoft Oracle Integration Cloud Tibco) (Required) CompTia Security Certification (Highly Desired) CySA Certification (Highly Desired) CISM Certification (Highly Desired) CISA Certification (Highly Desired) Familiarity with Scripting & Programming languages (Python Power Shell .Net) (Desired) Familiarity with Cybersecurity platforms (CrowdStrike) (Desired)
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.