Devops with Application Security

  • Full-time

Company Description

Describe what makes your company great

Job Description

Responsibilities
Participate in the implementation of full CI/CD pipeline lifecycle on hybrid environment i.e. On-prem and Cloud.
Implementation of Continuous Integration for .Net applications with Azure DevOps Service and TFS 2018. Creation of CI pipeline and integrate with Static Code Analysis (Fortify), Security, Testing, and Packaging.
Ensure Application Teams have full visibility on all identified vulnerabilities and manage exceptions in a timely manner
Database dacpack file creation and deployment on database servers using CI/CD pipeline.
Migrating TFS projects to GitLab service.
Work with Application teams and suggest the best practices in DevOps methods by ensuring compliance with the standards and best practices of Deloitte.
Consult on DevSecOps requirements from diverse application/line of business partners
Ensure that the service’s uptime and response time SLAs/OLAs are met or surpassed
Design action plans to address CI/CD platform/tools/solutions’ shortcomings and difficulties
Ensure incident tracking tools are updated in accordance with established norms and processes, gather all essential data and document any discoveries and concerns
Evaluates, develop, and implement secure solutions, based on approved enterprise security architecture lead security architect reviews, reviews
Participate in and lead a range of application security activities from Business-as-usual (BAU) application security assessments to organizational changing project enhancements
 

Qualifications
Experience in SDLC process and secure coding practices.
Expertise on the full stack tools used to deploy and manage web applications; CICD with Git and Jenkins.
Expertise on hosting and managing micro-services with clarity on IaaS and PaaS concepts.
Expertise on scripting languages (.NET preferably).
Experience on Automating and orchestrating infrastructure.
Experience on container orchestration tools like ECS, Kubernetes.
Experience in monitoring and analyzing system logs and RCA for site reliability and performance.
Experience in Serverless deployments, containerization (Docker), load balancing, auto scaling.
Good knowledge on Linux, Windows and tomcat Apache environments.
Experience with web application testing (Web, API and Mobile) and industry standards like OWASP, SANS, MITRE etc.
Shall have knowledge about threat modelling and Application Risk Assessment.
Understanding of TFVS/GIT Branching and Merging process and managing multiple source control repos
 

Additional Information

All your information will be kept confidential according to EEO guidelines.