Marsh

DevSecOps & Secure-SDLC Engineer

Marsh
Apply
1 month ago
Cluj-Napoca, RomaniaSenior

Responsibilities

  • Lead DevSecOps and Secure-SDLC initiatives and enhance the company’s Secure-SDLC framework.
  • Select, standardize, assess, and conduct proofs of concept for application security tools.
  • Integrate Secure-SDLC requirements and security policies into DevSecOps processes for traditional, cloud, and container workloads.
  • Define and enhance application security requirements and standards for agile development methods.
  • Advise application security leadership on shift-left practices, application security tools, standards, and process improvements.
  • Assess and rationalize existing security tooling across Software Development Lifecycle processes.
  • Draft clear Secure-SDLC and DevSecOps documentation and process guidelines for internal customers.
  • Assess the impact of security industry publications and trends on application security programs, tooling roadmaps, and processes.
  • Promote secure coding standards and Global Information Security and Global Application Security priorities.
  • Design, implement, and roll out DevSecOps automation and toolchain integrations.
  • Automate and integrate security scanning and analysis tools into DevSecOps pipelines.
  • Implement sensors to collect metrics for statistics and reporting.
  • Serve as the subject matter expert for Secure-SDLC and DevSecOps.
  • Assess tooling and remediation for threats and vulnerabilities in software, applications, and hosting environments.

Requirements

  • At least 5 years of DevSecOps and Secure-SDLC work experience.
  • CISSP, CSSLP, cloud security, DevSecOps automation, or a similar qualification is required.
  • Post-secondary education or equivalent experience as a DevSecOps Engineer.
  • Experience developing, enhancing, and implementing Secure-SDLC frameworks.
  • Experience designing and implementing Secure-SDLC processes and supporting tooling.
  • Hands-on experience automating and integrating security scanning and analysis tools into DevSecOps pipelines.
  • Experience with software and application analysis tools such as SAST, DAST, SCA, threat modeling, and supply-chain security.
  • Experience with one or more programming languages.
  • Familiarity with OWASP Top 10, SANS Top 25, and CWE security frameworks.
  • Ability to identify application security requirements and develop solutions using industry best practices.
  • Ability to assess security tooling and vulnerability remediation within software, applications, and hosting environments.

Benefits

  • Hybrid work arrangement requiring at least three days per week in the Cluj-Napoca office.
  • Professional development opportunities, interesting work, and supportive leadership.
  • Inclusive and collaborative culture with opportunities to create solutions and make an impact.
  • Yearly budget and flexible benefits package of up to 20% of annual salary.
  • More than 30 days off, including 25 legal days, a birthday day off, public holiday replacement days, and extra buy/sell options.
  • Performance bonus scheme.
  • Matching charity contributions, charity days off, and the Pay it Forward charity challenge.
  • Core benefits including pension, life and medical insurance, meal vouchers, and travel insurance.

Categories

Marsh

About Marsh

10,000+ employees
Contact me