IT- Staff Software Security Engineer
Core
Designing and implementing software security controls for cloud and on-premise environments, integrating security into CI/CD pipelines, and managing the secure software development lifecycle.
Role type
Staff Software Security Engineer (DevSecOps)
Builds
Secure CI/CD pipelines, security tool integrations (WAF, CDN, SAST, DAST, SCA), and cloud infrastructure security.
Domain
Cybersecurity, Cloud Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
CI/CD security integration, risk management and compliance (NIST, ISO 27001, CIS), vulnerability assessment and remediation, incident response and forensics, cloud security (AWS, Azure, GCP), network security (firewalls, IDS/IPS, SIEM), application security testing (SAST, DAST, SCA), attack surface management, secure configuration management for Windows/Linux/Mac.
Preferred skills
Mergers and acquisitions security knowledge.
Technologies
Perforce, Github, AWS, Azure, GCP, WAF, CDN, SIEM, SAST, DAST, SCA.
Responsibilities
Integrate security tools at source code repo, build environment, and artifactory levels; develop and support the secure software development lifecycle; conduct penetration testing and attack surface management; manage security incidents from detection to resolution; identify security gaps and provide mitigation strategies; document vulnerability assessment results.
Seniority
Staff, hands-on IC with strategic oversight