DevSecOps Engineer (m/f/d)

at  Epam Systems

München, Bayern, Germany -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate27 Aug, 2024Not Specified28 May, 20245 year(s) or aboveAws,Vulnerability Management,Kubernetes,Network Security,Software Development Methodologies,Application Security,Medical Devices,Azure,Devops,Infrastructure,Defense,Ruby,Code,Python,Threat Modeling,Security Testing,Regulations,Iso,Security OperationsNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

REQUIREMENTS

  • Security-focused or Computer Science university degree (Bachelors) OR equivalent experience
  • 5+ years’ experience in DevOps, with significant exposure to security aspects
  • Proficiency in one or more programming languages, predominantly used in DevOps like Python, Ruby, or Go
  • Practical experience with CI/CD pipelines and tools such as Jenkins, and AWS CodePipeline
  • Experience with container orchestration tools like Kubernetes and Docker, and cloud environments such as AWS, Azure, or Google Cloud
  • Relevant certifications such as AWS/Azure Certified DevOps Engineer, or similar qualifications are considered an advantage
  • Experience with medical security governance and IT general control frameworks such as DSOMM, HIPPA, ISO 13485, NIST CSF, NIST 800-53, MDR (EU), etc., is a huge advantage
  • Deep understanding of secure Infrastructure as Code (IaC) strategies and signed image verification practices
  • Experience in using Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools for code analysis
  • Security Knowledge: Solid understanding of network access, identity, access management, applied cryptography, network security methodologies, and secure software development methodologies
  • Knowledge and experience with identifying and understanding the most common application security vulnerabilities (OWASP Top 10)
  • Agile mindset, Continuous Quality and Process Improvement
  • Deep expertise with more than one of the following area
  • API security
  • DevSecOps practices
  • Identity and Access Management
  • Compliance & regulations for medical devices
  • Cloud Security Architecture & Controls
  • Security Architecture & Models in Healthcare
  • Zero trust & Defense in depth principles
  • Network security
  • Infrastructure and application security assessment
  • Vulnerability management
  • Application Security
  • IoT Security architecture
  • CI/CD tooling (SAST, DAST, SCA, Secret Scanner. Secure Gates, Image Signed, etc)
  • Threat Modeling and Secure-by-Design
  • Security Operations

Responsibilities:

ABOUT THE ROLE

EPAM is looking for a dedicated DevSecOps Engineer to automate and optimize our development processes and ensure secure CI/CD pipelines. Working closely with our Security Architect, your main responsibility would be to reinforce our security posture across our development teams and digital portfolio.
At EPAM, you will work with the most recent advancements in tech, ensuring that our innovative solutions stay at the cutting edge of technology trends while also being safe and reliable. Our DevSecOps team is composed of globally recognized experts who take pride in driving real impact in the tech security domain.
We value flexibility and offer a modern approach to work with a hybrid model. You can enjoy the privilege of working from home, backed by occasional visits to client sites or our office. This is an exceptional opportunity to lead and learn, while shaping the future of secure technology deployment.

RESPONSIBILITIES

  • Collaborate with the Security Architect to drive the Security Architecture & Solutions for our core digital portfolio and future digital products
  • Automate repetitive tasks and implement secure CI/CD pipelines, enhancing productivity and reducing errors
  • Own the implementation and continuous improvement of security tooling across various areas including static/dynamic analysis, dependency scanning, and secrets detection
  • Implement appropriate technical and organizational security controls to mitigate identified risks, with a focus on automating these measures wherever possible
  • Promote and facilitate Security-By-Design principles across the development team, bridging the gap between operations and security
  • Implement Infrastructure as Code (IaC) security measures, protecting integral aspects of our infrastructure and ensuring secure deployments
  • Embed security within the DevOps lifecycle, including the design and execution of signed image verification systems to ensure the authenticity and integrity of images
  • Conduct ongoing security training for the development team to ensure awareness and compliance


REQUIREMENT SUMMARY

Min:5.0Max:10.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Software Engineering

Graduate

Computer Science

Proficient

1

München, Germany