- Company Name
- MetroStar
- Job Title
- Sr. DevSecOps Engineer II (5977)
- Job Description
-
Job title: Sr. DevSecOps Engineer II
Role Summary: Design, implement, and maintain secure software delivery pipelines that integrate automated security testing, vulnerability scanning, and compliance checks throughout the CI/CD lifecycle. Lead IaC development, secure cloud resource provisioning, and incident response, ensuring code and infrastructure meet enterprise security standards.
Expectations: Deliver high‑quality, secure, and reliable software solutions by embedding security into all development and operations activities. Collaborate cross‑functionally with developers, ops, and security teams to enforce best practices, remediate findings, and maintain continuous security monitoring.
Key Responsibilities:
- Collaborate with development, operations, and security teams to embed security into the software development lifecycle.
- Design, build, and sustain CI/CD pipelines with automated security testing, vulnerability scanning, and compliance checks.
- Develop and manage IaC templates (Terraform, CloudFormation, Ansible) ensuring security best practices for cloud and on‑prem resources.
- Conduct regular security assessments, code reviews, and penetration testing; remediate vulnerabilities.
- Monitor logs and system metrics to detect and respond to security incidents.
- Implement and manage IAM solutions, including authentication, authorization, and least‑privilege access controls.
- Provide secure coding guidance to software engineers and assist in issue remediation.
- Participate in incident response, investigation, and mitigation efforts.
- Author and maintain security policies, procedures, and documentation.
Required Skills:
- 7+ years in DevSecOps or equivalent role focused on secure SDLC integration.
- Proficiency with CI/CD tools (Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium, Fortify, Acunetix, Prisma Cloud).
- Expertise in IaC tools (Terraform, CloudFormation, Ansible).
- Strong experience with AWS, Azure, or GCP security architecture and services.
- Advanced scripting in Python and Bash for automation and tooling.
- Knowledge of IAM, VPN, Zero Trust principles, network segmentation, and encryption.
- Experience with penetration testing frameworks and vulnerability management.
- Ability to analyze logs, alerts, and incident data; conduct root cause analysis.
Required Education & Certifications:
- Minimum Bachelor’s degree in Computer Science, Information Security, or related field.
- Professional certifications such as CISSP, CCSP, CISM, AWS Certified Security – Specialty, or equivalent.
- Active TS/SCI clearance with CI poly.