DevSecOps Engineer
ResponsibilitiesDefine and enforce application deployment security design across Kubernetes, Service Fabric, and legacy systems.Implement NeuVector for container runtime security and vulnerability detection.Manage JFrog code scanning for artifact integrity and compliance.Oversee PKI lifecycle management using OpenBoa for secure secrets distribution.Harden DevOps tooling (TerraKube, AWX) and IaC templates for secure deployments.Develop mitigation strategies for vulnerabilities in containers, VMs, and supporting infrastructure.Automate compliance reporting and policy enforcement (Policy as Code).Conduct threat modeling and risk assessments.Required SkillsKubernetes security (network policies, RBAC, container hardening).DevSecOps tools: SonarQube, Snyk, OWASP ZAP, Trivy, NeuVector.Compliance automation and reporting frameworks.Secrets management and secure artifact handling.Experience with CI/CD security integration (SAST, DAST, SCA).Familiarity with cloud-native security (IAM, security groups, audit logging).Nice to HaveCertified DevSecOps Professional (CDP) or equivalent.Experience with GitOps security workflows.Knowledge of threat modeling and risk assessment.