drjobs Information Security Engineer 4 - DevSecOps Engineer

Information Security Engineer 4 - DevSecOps Engineer

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Iselin, NJ - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

USA-NJ-ISELIN-194 Wood Ave S-112265
Senior DevSecOps Engineer Software Composition Analysis (SCA) & Container Security
Key Responsibilities:

- Managing security automation tools with main focus on SCA (i.e. Checkmarx One BlackDuck) and other tools in the ecosystem along with supporting operational management with regularily scheduled upgrade of the tools.
- Interface with various internal teams ServiceNow AVR DevOps and vulnerability operations team to make sure SCA vulnerabities are identified and recorded per the application security policies and guidance.
- Collaborate with security architecture teams to design vulnerability management workflow establish best practices and design guidance to optimize experience for developers
- Security training and outreach as needed for internal development teams
- Adversarial security analysis on various application security requirements as requested from various CIO teams research and recommend cutting-edge tools and industry best practices.
- Work with application security governance teams risk & compliance partners on audits (e.g. SOC 2 PCI-DSS) and recommending relevant policies.
- Collaborate with CTO pipeline teams to improve code quality and vulnerability detection on OpenSource code signing and SBOM creation
- Analyze enhance architect and support container security tools and platforms
- Design and build advanced security solutions to strengthen open source software supply chains for effective automation and management.

7 years of experience as Application Security and DevSecOps engineer collaborating with developers to adopt and mature secure development
Solid background in software development experience in one or more of programming languages .Net C# Java RUST C
Ability to write automation scripts in Python PowerShell to support internal projects
Experience with CI/CD pipelines and related technologies (e.g. GitHub Jenkins Maven Artifactory Harness Xray Curation)
Good understanding of Secure Software development lifecycle
Strong knowledge of OWASP Top 10 or CWE
Detailed oriented must be able to create documentation on different SCA procedures and tool configuration.
Familarity and experience with AI tools supporting false positives reduction auto code remediation open source threat intelligence would be preferred.
Experience with Jira/Confluence is required
Strong problem-solving and analytical skills
Certification in information security (CISSP CISM CEH etc.)
Experience with container security working with technologies like k8s and container technologies such as Openshift
Experience generating Software Bill of Materials (SBOMs) using CycloneDX or SPDX managing or utilizing dependency track

Employment Type

Full-time

Company Industry

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.