Infrastructure Security Engineer II - Cloud & DevSecOps

Trung tâm Công nghệ Thông tin
Hồ Chí Minh
26-ITC-0116
In this role, you will be responsible for integrating security practices into our DevOps processes, ensuring that our software is both secure and delivered efficiently. As a DevSecOps Engineer, you will work closely with development, operations, and security teams to automate security measures, conduct vulnerability assessments, and respond to security incidents in real-time. This role offers the opportunity to make a significant impact on our company's security posture and contribute to the development of innovative solutions.

Mô tả công việc

  • Integrate security best practices into the DevOps pipeline, ensuring secure software delivery.
  • Conduct regular vulnerability assessments and provide recommendations for remediation.
  • Collaborate with development, operations, and security teams to design and implement security solutions.
  • Automate security processes, including vulnerability scanning and incident response.
  • Monitor security metrics and prepare reports for stakeholders.
  • Stay up-to-date with the latest security trends, threats, and technologies.
  • Respond to security incidents and lead post-incident investigations.
  • Provide training and guidance to team members on security best practices.

Yêu cầu công việc

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Proven experience in a DevSecOps or related role.
  • Proficiency in security and DevOps tools such as Jenkins, Docker, Kubernetes, and security scanning tools.
  • Strong understanding of cloud platforms (e.g., AWS, Azure, GCP) and their security features.
  • Experience with automation and scripting languages (e.g., Python, Bash).
  • Familiarity with continuous integration and continuous delivery (CI/CD) pipelines.
  • Excellent problem-solving and analytical skills.
  • Strong communication and leadership abilities.
  • DevOps and Security Tools: Proficiency in tools such as Jenkins, Docker, Kubernetes, and security scanning tools.
  • Vulnerability Assessment: Experience in identifying and mitigating security vulnerabilities.
  • Security Integration: Ability to embed security protocols into the DevOps pipeline.
  • Incident Response: Skills in responding to and managing security incidents.
  • Automation: Expertise in automating security processes and integrating them into CI/CD pipelines.