3 months ago
San Antonio, TX, USASenior
Responsibilities
- Design, implement, and maintain security controls in GitHub and Azure DevOps CI/CD pipelines.
- Integrate SAST, SCA, DAST, container, and secrets-scanning tools into delivery pipelines.
- Develop automation scripts for secure deployments, monitoring, and operational efficiency.
- Secure AWS environments, IAM, OIDC, secrets management, KMS encryption, Docker, Kubernetes, and container registries.
- Design and maintain infrastructure-as-code using Terraform, CloudFormation, or AWS CDK.
- Implement logging, monitoring, alerting, and observability for cloud workloads.
- Monitor threats, indicators of compromise, compliance gaps, vulnerabilities, and remediation activities.
- Participate in incident response, investigation, and recovery.
- Support PCI-DSS, SOC 2, and NIST audit and compliance requirements with GRC teams.
- Review code, infrastructure changes, and releases for security risks and enforce secure SDLC practices.
- Provide security architecture guidance, mentor team members, and promote security automation.
- Develop and track security metrics, KPIs, and pipeline telemetry.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- At least five years of experience in DevSecOps, cloud security, or security engineering.
- Hands-on experience with GitHub, GitHub Actions, or similar CI/CD tools.
- Strong AWS cloud services and security-controls expertise.
- Experience with Terraform or other infrastructure-as-code tools.
- Experience with Docker and Kubernetes, including container orchestration and security.
- Knowledge of IAM, OIDC, secrets management, and KMS.
- Understanding of Git workflows, branching strategies, pull requests, OWASP Top 10, and application security principles.
- Proficiency in Python, Bash, or Go.
- Experience with Mend, SonarQube, Prowler, Trivy, OWASP ZAP, or Burp Suite.
- AWS Certified Developer – Associate certification is required at the time of hire.
- AWS Certified DevOps Engineer – Professional certification is required within six months of hire.
- AWS Certified Security – Specialty, AWS Certified SysOps Administrator – Associate, AWS Certified Solutions Architect – Associate, CISSP, CCSP, or GIAC certifications are desired as specified.
- Experience with SIEM/SOAR platforms, security automation, financial or regulated environments, and offensive security practices is preferred.
- Knowledge of AI/ML security risks is preferred.
Benefits
- Competitive overall compensation package.
- Work/life balance, employee engagement activities, recognition awards, and Years of Service awards.
- Career enhancement opportunities, Leadership Academy, and Mentor Program.
- Continuing education and career certifications.
- Healthcare coverage options, traditional and Roth 401(k) retirement plans, and a wellness program.
- Benefits are subject to employee eligibility.
- Substance-free workplace with pre-employment drug testing; tobacco-user hiring restrictions apply as allowed by law.