|
Essential
- 5+ years delivering platform or complex software products in Agile environments with cross squad coordination.
- Strong DevOps/CI CD experience: pipeline design and implementation (Jenkins, GitLab CI, Azure DevOps), IaC (Terraform/CloudFormation), container orchestration (Kubernetes).
- Demonstrable hands on security engineering experience: threat modelling, secure architecture, SAST/DAST/SCA tooling, vulnerability management and remediation workflows.
- Network engineering knowledge: TCP/IP, routing, firewalls, VPNs, load balancers, micro segmentation, and secure connectivity patterns for cloud and on prem.
- Experience embedding security gates into release processes and enforcing compliance requirements (PCI/DSS, ISO27001, NIST, orequivalent).
- Familiarity with secrets management, PKI, IAM, RBAC, and least privilege access models.
- Strong release and delivery management skills: milestone management, release gating, environment management, rollback strategies.
- Solid experience with test automation, environment provisioning, and operational readiness practices.
- Excellent communicator capable of translating technical security risks to business stakeholders.
- Proven leadership/mentoring skills and a continuous improvement mindset.
Desirable
- Experience with cloud security controls on AWS/Azure/GCP and managed networking/security services (NSGs, Security Groups, WAF, VPC/VNet designs).
- Certifications: CISSP, OSCP, CEH, CCNP/CCIE (network), Certified DevOps or cloud security certs (e.g., AWS/Azure/GCP security).
- ITIL/service transition, incident response, orSOC integration experience.
- What success looks like
- Repeatable, secure release process with measurable reduction in security incidents and vulnerabilities in production.
- Automated CI/CD pipelines with integrated security testing and demonstrable improvement in mean time to deploy and to remediate vulnerabilities.
- Stable, compliant platform accepted into operational support with clear runbooks, monitoring, and SLAs.
- Strong cross team collaboration, JIRA hygiene, and traceable evidence for audits.
|