Responsibilities
- Lead end-to-end secure software development lifecycle processes, including coding standards, threat modeling, security checkpoints, policy-as-code, and audit-ready documentation, in collaboration with the Software Architect.
- Identify, assess, and resolve security vulnerabilities in Python, Go, and TypeScript/React codebases by working directly with developers to prioritize and implement effective fixes.
- Build, strengthen, and maintain CI/CD pipelines using platforms like GitHub Actions, GitLab CI, or Jenkins, embedding security measures seamlessly into development workflows.
- Deploy and manage security tools across the development pipeline, covering static and dynamic analysis, software composition, secret detection, container inspection, and dependency tracking.
- Enforce secure software supply chain practices, including artifact signing, SBOM creation, and provenance verification, to safeguard build and release integrity.
- Oversee management of secrets, credentials, and signing keys in pipelines, ensuring least-privilege access, secure storage, and regular rotation.
- Collaborate with development teams to review code, evaluate security risks, and suggest actionable improvements that maintain delivery speed.
- Assist in responding to security incidents involving applications or platforms, supporting root cause analysis and implementation of long-term solutions.
- Support compliance audits by preparing evidence and documentation for standards such as ISO 27001, SOC 2, PCI DSS, or FedRAMP, particularly around CI/CD and engineering controls.
- Guide engineers in secure coding practices and promote a proactive security culture integrated into design, development, and release cycles.
Compensation
Competitive salary and benefits package
Work Arrangement
Hybrid or remote options available
Team
Collaborative engineering environment with cross-functional teams
Responsibilities (10)
- Lead end-to-end secure software development lifecycle processes, including coding standards, threat modeling, security checkpoints, policy-as-code, and audit-ready documentation, in collaboration with the Software Architect.
- Identify, assess, and resolve security vulnerabilities in Python, Go, and TypeScript/React codebases by working directly with developers to prioritize and implement effective fixes.
- Build, strengthen, and maintain CI/CD pipelines using platforms like GitHub Actions, GitLab CI, or Jenkins, embedding security measures seamlessly into development workflows.
- Deploy and manage security tools across the development pipeline, covering static and dynamic analysis, software composition, secret detection, container inspection, and dependency tracking.
- Enforce secure software supply chain practices, including artifact signing, SBOM creation, and provenance verification, to safeguard build and release integrity.
- Oversee management of secrets, credentials, and signing keys in pipelines, ensuring least-privilege access, secure storage, and regular rotation.
- Collaborate with development teams to review code, evaluate security risks, and suggest actionable improvements that maintain delivery speed.
- Assist in responding to security incidents involving applications or platforms, supporting root cause analysis and implementation of long-term solutions.
- Support compliance audits by preparing evidence and documentation for standards such as ISO 27001, SOC 2, PCI DSS, or FedRAMP, particularly around CI/CD and engineering controls.
- Guide engineers in secure coding practices and promote a proactive security culture integrated into design, development, and release cycles.
Available for qualified candidates