Responsibilities:
· Embed security into CI/CD pipelines and infrastructure as code (IaC).
· Perform security assessments of applications, containers, and cloud infrastructure.
· Automate security testing and monitoring using tools like Snyk, Aqua, or Twistlock.
· Collaborate with development and operations teams to ensure security best practices.
· Implement and manage secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager).
· Monitor systems for security vulnerabilities and respond to incidents.
· Develop and enforce policies, standards, and procedures for secure development and deployment.
· Conduct threat modeling and risk assessments.
· Stay current with emerging security threats, vulnerabilities, and technologies.
· Work with Firewall and Web Application Firewall (WAF) policies and configurations to enhance application and infrastructure security.
· Perform security testing using DSAT (Dynamic Security Application Testing) and SAST (Static Application Security Testing) as part of the SDLC.
Office environment: When you come to our b_labs office, you'll find creative workspaces and an open design to foster collaboration between teams.
Flexibility: You know best whether you want to work from home or in the office.
Equipment: From "Day 1" you will receive all the equipment you need be successful at work.
· Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or related field.
· 2 years of proven experience in DevOps, security engineering, or cloud infrastructure.
· Strong knowledge of CI/CD tools (e.g. Jenkins, GitHub Actions, GitLab CI, CircleCI).
· Experience with IaC tools like Terraform, CloudFormation, or Ansible.
· Proficiency with cloud platforms (AWS, Azure, GCP).
· Familiarity with containerization and orchestration (Docker, Kubernetes).
· Knowledge of vulnerability management and security tools (e.g. Nessus, OWASP ZAP, Trivy).
· Strong scripting skills (Python, Bash, etc.).
· Understanding of compliance standards (SOC 2, ISO 27001, HIPAA, etc.).
· Good knowledge of Firewalls and Web Application Firewalls (WAF).
· Good knowledge of DSAT (Dynamic Security Application Testing) and SAST (Static Application Security Testing).