DevSecOps engineer ensuring security practices in software development lifecycle at Ford. Collaborating with teams and implementing secure coding practices.
Responsibilities
Perform security-focused code reviews.
Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
Knowledge of Risk mitigation techniques and fixing the code bugs.
Monitoring the processes during the entire lifecycle for its adherence and updating or creating new processes for improvement.
Support and consult with product and development teams in the area of application security. Identifying and deploying cybersecurity measures by continuously performing vulnerability assessment and risk management.
Providing security training and outreach to internal development teams.
Mentoring, guiding team members and customers.
Monitoring, measuring customer experience and KPIs.
Use security tools for identifying and mitigating vulnerabilities.
Able to work well with software development teams.
Experience identifying security issues through code review.
Excellent and professional communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
Familiarity with some common security libraries and tools (e.g. static analysis tools).
Familiarity and ability to explain common security flaws and ways to address them (e.g. OWASP Top 10).
Experience in integrating, monitoring and improving DevSecOps tools and processes, automate routine tasks and improve system reliability.
Development or scripting experience and skills. (preferable Python knowledge).
Designing and implementing Zero Trust Security model, automated enforcement, and monitoring of security controls, vulnerability management, code-based compliance and gate reviews, platform-based security controls and guardrails.
Requirements
Bachelor (undergraduate) degree in a relevant field (Computer Science, Software Engineer, Security, or others) OR an equivalent combination of education, training, and experience.
Minimum of 5 years of professional experience with any combination of at least 2 technical disciplines, including the following: DevSecOps, cloud security, network security, application security, mobile security, secure development methodologies, software development and coding, identity management, authentication and authorization, network architecture, system administration, and systems engineering.
Desirable Certified DevSecOps Professional (CDP), Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security (CKS) and HashiCorp Certified: Terraform Associate.
Client Support Advisor delivering face - to - face service to clients in Scottish Borders. Helping them understand and access benefits with tailored one - to - one support.
Senior IT Security Engineer protecting IT Security platforms for one of the largest e - commerce sites in the U.S. Designing and managing security solutions to ensure network safety.
Cybersecurity Engineer supporting a critical U.S. Navy program enhancing national security and operational readiness. Designing and implementing secure system architectures for Navy combat systems and environments.
CyberSecurity Team Lead overseeing vulnerability management and security integration for Mistral's AI solutions. Collaborating with teams to enhance security posture and protect infrastructure.
Support Engineer providing technical assistance for F5 customers with cloud - based solutions. Collaborating with internal teams to resolve issues and advocate for customer needs.
Technical Implementation Manager overseeing implementation of complex systems for law enforcement and corporate security. Collaborating with stakeholders to facilitate smooth transitions and optimize solutions.