Unleash your potential: What you will be doing and owning:
• Design, build, and operate secure CI/CD pipelines with integrated SAST, DAST, SCA, secrets scanning, and container image scanning, making the secure path the easy path for product teams.
• Harden and automate AWS and/or Azure infrastructure using infrastructure-as-code, with security policies enforced through OPA, Sentinel, or native policy engines.
• Own container and orchestration security across Docker and Kubernetes, including image provenance, runtime protection, network policies, and admission controls.
• Implement and tune cloud security posture management, vulnerability management, and threat detection capabilities, and partner with engineering teams to drive findings through remediation.
• Build and maintain secure secrets management, identity, workload identity, service mesh mTLS, and least-privilege access patterns.
• Lead threat modeling and secure design reviews for new services and architectures, partnering with product engineering early in the development lifecycle.
• Respond to security events and lead post-incident analysis, improving detection, alerting, and runbooks after each incident.
• Design and manage cloud networking, including VPC/VNet architecture, subnetting, routing, NAT, peering, transit gateways, private endpoints, and hybrid connectivity.
• Operate edge and traffic-layer security, including load balancers, API gateways, WAF, DDoS protection, CDN configuration, DNS management, and TLS certificate lifecycle/PKI automation.
• Implement GitOps-based delivery using Argo CD or Flux with Helm/Kustomize and progressive delivery patterns such as blue-green and canary releases with automated rollback.
• Build and operate observability capabilities across metrics, logging, tracing, and alerting, with defined SLOs and actionable, low-noise alerts.
• Manage artifact repositories and software supply-chain controls, including image registries, SBOM generation, artifact signing, and provenance using technologies such as Sigstore/Cosign and SLSA.
• Drive capacity planning, autoscaling, and cloud cost optimization across compute, storage, and network layers without compromising security.
• Champion compliance-relevant engineering controls, including PCI DSS and SOC 2, and automate evidence collection wherever possible.
• Mentor engineers on secure coding and operational security practices, acting as a force multiplier rather than a gatekeeper.