- Escritório em Bengaluru
Key Responsibilities: Information Security Responsibilities (Primary)
- Take complete ownership of the organization's information security posture, including developing and enforcing security policies, standards, and procedures.
- Perform regular security risk assessments, penetration testing, and vulnerability scans to identify and address risks.
- Monitor and respond to security incidents, investigating alerts and coordinating resolution independently.
- Integrate security best practices into DevOps workflows, including CI/CD pipelines, infrastructure provisioning, and configuration management.
- Respond to and take full action on user-submitted reports, emails, and vulnerabilities.
- Manage the lifecycle of vulnerability reports from identification through to remediation, working closely with internal teams.
- Answer client security questionnaires with detailed and accurate responses aligned with company policies and standards.
- Implement and manage security tools such as firewalls, SIEM solutions, intrusion detection/prevention systems (IDS/IPS), and secret management solutions.
- Ensure compliance with security frameworks and regulations, including SOC2, ISO 27001, GDPR, and other relevant standards.
- Stay up-to-date with emerging security threats and proactively recommend countermeasures.
- Prepare and maintain security documentation, including audit reports, incident response plans, and risk assessments.
DevOps Responsibilities (Secondary)
- Design, implement, and manage CI/CD pipelines to enable fast, reliable, and secure application deployments.
- Build and maintain Infrastructure as Code (IaC) using tools like Terraform, Cloud Formation, or Ansible.
- Manage and monitor containerized environments using Docker and orchestration platforms like Kubernetes.
- Architect scalable, secure, and implement cost-efficient cloud-based infrastructure in AWS.
- Collaborate with development teams to optimize and automate build, deployment, and release processes.
- Implement and manage observability tools for monitoring, logging, and alerting (e.g., Prometheus, Grafana, ELK Stack).Troubleshoot and resolve system performance issues and bottlenecks.
- Automate repetitive operational tasks using scripting languages like Python, Bash and other programming languages.
- Ensure the availability and reliability of systems through robust disaster recovery and failover strategies.
SKILL REQUIREMENTS
- Strong problem-solving and analytical skills, with the ability to take initiative and independently drive solutions.
- Excellent communication and collaboration skills for cross-functional work.
- Ability to prioritize tasks, work under pressure, and manage multiple responsibilities simultaneously.
- Detail-oriented and proactive in identifying and addressing security and operational challenges.
SKILL REQUIREMENTS
- Strong problem-solving and analytical skills, with the ability to take initiative and independently drive solutions.
- Excellent communication and collaboration skills for cross-functional work.
- Ability to prioritize tasks, work under pressure, and manage multiple responsibilities simultaneously.
- Detail-oriented and proactive in identifying and addressing security and operational challenges.
WORK EXPERIENCE
- Experience:5-7 years of experience in DevOps, with a proven track record of managing secure, scalable infrastructure.
- Hands-on experience with cloud environments, particularly AWS, including services like EC2, S3, IAM, and VPC.
- Strong expertise in CI/CD tools such as Jenkins, GitLab CI, or CircleCI.
- Solid experience with containerization (Docker) and orchestration (Kubernetes).Demonstrated ability to integrate security practices into DevOps workflows, including vulnerability scanning and compliance automation.
- Proven experience in managing information security independently, including incident response, policy development, and risk management.
- Hands-on experience with security tools like SIEM, vulnerability scanners, IDS/IPS, and endpoint protection solutions.
- Familiarity with regulatory compliance frameworks such as SOC2, ISO 27001, or GDPR.
- Proficiency in scripting and automation using Python, Bash and other programming languages.
- Certifications (Preferred):AWS Certified DevOps Engineer or AWS Certified Security – Specialty.
- Security certifications such as CISSP, CEH, CISM, or CompTIA Security+.
EDUCATION REQUIREMENTS
- Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. Equivalent work experience will also be considered.
Candidatar-se agora