You are a Senior Security Engineer with a strong focus on application security and a deep understanding of securing CI/CD pipelines. You are experienced in collaborating with development and DevOps teams to integrate security throughout the software delivery lifecycle. You have a proactive mindset strong technical skills and a commitment to staying ahead of emerging threats and vulnerabilities. Your attention to detail and ability to automate security processes make you a key partner in ensuring secure software delivery.
Does this sound like you If so keep reading and apply today!
What Youll Do:
Design and implement security controls and tools within CI/CD pipelines to protect against threats and vulnerabilities.
Conduct security assessments code reviews and penetration testing on applications and infrastructure deployed through CI/CD workflows.
Integrate security tools (e.g. SAST DAST dependency scanning) into CI/CD systems such as Jenkins GitLab CI/CD GitHub Actions or CircleCI.
Collaborate with DevOps teams to automate security checks and ensure secure configuration of build and deployment environments.
Monitor and respond to security incidents related to CI/CD processes including artifact integrity and pipeline tampering.
Develop and maintain documentation for secure CI/CD practices policies and procedures.
Stay uptodate with emerging threats vulnerabilities and security technologies relevant to CI/CD and cloudnative environments.
Educate and train development teams on secure coding practices and CI/CD security principles.
Ensure compliance with regulatory standards (e.g. SOC 2 ISO27001 in the software delivery lifecycle.
What You Have:
3 years of experience in security engineering DevSecOps or a related role.
Handson experience securing CI/CD pipelines using tools like Jenkins GitLab CI/CD GitHub Actions or similar platforms.
Proficiency with security tools such as Sonarcloud Github Security
Strong understanding of software development lifecycle (SDLC) and DevOps practices.
Familiarity with containerization and orchestration technologies (e.g. Docker Kubernetes) and their security implications.
Knowledge of cloud platforms (e.g. AWS) and their security configurations.
Experience with scripting languages (e.g. Python Bash) for automation and tool integration.
Excellent problemsolving skills and attention to detail.
Extras you bring
Experience with InfrastructureasCode (IaC) tools like Terraform or CloudFormation.
Beware of recruitment scams impersonating the Polly brand or our employees. Our team communicates only through official Polly channels and we will never ask for sensitive information over text or conduct textonly interviews. If you are ever suspicious or in doubt reach out to us directly at . We care deeply about this network and your experience.
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.