Data Engineer
Core
Review and evaluate results from automated security scans (SAST, SCA, vulnerability, and cloud security), consolidate reporting on security findings, and support the development of DevSecOps mechanisms.
Role type
Senior Information Security Management Specialist
Builds
DevSecOps mechanisms along CI/CD pipelines
Domain
Information Security, IT Compliance, IT Risk Management
Deliverable
dashboards & analysis
Required skills
Information security experience, IT compliance, IT risk management, security standards knowledge, audit and assessment experience, agile software development knowledge, SAST/SCA/DevSecOps concepts, cloud security or AI in security interest
Preferred skills
CISSP certification, Secure-by-Design principles, Secure Coding principles, regulatory requirements knowledge (NIS2, ISO 27001), threat modeling, penetration testing, application reviews
Technologies
SAST, SCA, DevSecOps, CI/CD pipelines
Responsibilities
Review and evaluate results from automated security scans, consolidate reporting on security findings, support the development of DevSecOps mechanisms, advise on Secure-by-Design and Secure-Coding principles, create and maintain MIKE-specific security documentation, derive policies for playbooks and development guidelines, plan and execute individual security measures, serve as an interface to corporate IT security and external partners
Seniority
Senior, hands-on IC