Design, implement, and maintain secure CI/CD pipelines
Integrate automated security testing into software delivery processes
Configure and maintain security gates for build and deployment pipelines
Automate security validation throughout the SDLC
Integrate secrets scanning and software supply chain security controls into CI/CD workflows
Implement and manage Static Application Security Testing (SAST)
Integrate Software Composition Analysis (SCA) into development workflows
Configure Dynamic Application Security Testing (DAST) solutions
Support developers in vulnerability remediation and secure coding practices
Perform threat modeling, secure design reviews, and security risk assessments for new and existing solutions
Identify and mitigate software supply chain risks, including open-source dependency risks and secure build and release practices
Secure AWS, Azure, or GCP environments following security best practices
Implement Identity and Access Management (IAM) policies based on least privilege
Secure cloud networking, encryption, and key management
Review cloud configurations for security risks
Secure Docker images and container registries
Implement Kubernetes security controls, including RBAC, Pod Security Standards, Network Policies, and Admission Controllers
Configure runtime protection for Kubernetes workloads
Perform container image vulnerability assessments
Review and secure Terraform, CloudFormation, ARM, or Bicep templates
Integrate IaC security scanning into CI/CD
Maintain infrastructure security baselines
Analyze, prioritize, and track remediation of security findings
Work closely with engineering teams to resolve vulnerabilities
Improve vulnerability management processes and reporting
Prioritize vulnerabilities based on technical severity, exploitability, business impact, and overall security risk
Support penetration testing activities by reviewing findings, coordinating remediation, and tracking remediation follow-up
Develop automation using Python, Bash, or PowerShell
Automate security scanning, reporting, alerting, and remediation workflows
Improve security operations through scripting and orchestration
Support compliance initiatives such as ISO 27001, SOC 2, PCI DSS, HIPAA, CIS Benchmarks, and NIST
Participate in internal and external security audits
Maintain security documentation and operational procedures.Collaboration
Partner with development teams to promote secure software development
Conduct architecture and security design reviews
Provide technical guidance on DevSecOps best practices
Mentor engineers on secure development principles
Communicate security risks and remediation priorities clearly to both technical and non-technical stakeholders