Security Development Engineering
Location: Herndon, VA, us
Company Description
Entrusted by companies with challenging Cyber Security and IT data management recruiting needs, Flex Staffing Resources identifies exceptional talent and cutting edge companies and brings them together.
Job Description
SecDevOps exists to bridge the gap between Security and Engineering. The position serves as the technical points of contact for security related activity that needs engineering or development focus. This position will be a hybrid position, and will require on-site attendance as required (i.e., training, assessment participation, team meetings, etc.).
This role serves as a “hands-on” senior-level security development engineer who will the responsible for interfacing with security engineering, operations, security and build teams. This individual will assist the GRC Control Assurance and SOC Vulnerability Management teams with the initial triage of vulnerabilities, using knowledge and experience to product an actional items for operations, or as necessary, and be point for escalations to Product or Cloud teams. This individual will review other team member responses and use in consideration of the final list. Additionally, this individual will be supporting the various assessments/audits by participating in interviews, managing operation and engineering escalations in support of assessment / audit activities. This can include, but not limited to, providing assistance and guidance on how the security controls are being addressed through automation, configuration or build as well as gathering evidence for the assessors. As required, this individual will also shepard vulnerabilities and/or findings through the remediation process. This individual is expected to be able to begin work almost immediately based on experience, once provided the environments, procedures and processes. Oversight and guidance will be provided as needed.
Qualifications
- Bachelor’s Degree in Computer Science / MIS / Information Technology, or equivalent experience in Information Security, Information Technology, or related technical discipline
- Experience with best practice identification and response to operating system and web application vulnerabilities, such as patching or otherwise mitigating known security issues.
- Ability to communicate complex security vulnerabilities to various audiences ranging in technical knowledge.
- Experience with various scanning tools including but not limited to Nessus, WebInspect and/or container scanners such as Clair, Trivy, Grype
- Exposure to information security standards such as DISA STIGs or CIS. Previous work with immutable image deployments/architecture.
- Experience leading efforts across multiple groups and security boundaries toward common goals.
- Ability to debug and optimize code and automate routine tasks.
- Systematic problem-solving approach coupled with strong communication skills and a sense of ownership and drive.
- Experience in tracking and creating various metrics, KPIs or OKRs.
- Experience with SDLC and Release processes
- Knowledge with patching and vulnerability remediation processes
- Ability to adapt to a high paced environment and workload
Experience with one or more of the following:
- C, C ++, Java, Python, Go, Perl, Ruby, or shell scripting.
- Experience working in a Cloud Environment – AWS, Azure, GCP
- Experience with JIRA Ticketing System Information Technology
- Experience with Service Now Ticketing System
- Experience working with containers or Kubernetes
- Experience with Unix / Linux/Windows operating system internals and administration (e.g., filesystems, inodes, system calls, hardening) and networking (e.g., TCP / IP, routing, DNS, network topologies, SDN).
- Understanding and practice with security frameworks such as NIST 800-53, NIST 800- 171, SOC 1 or SOC 2, or PCI
- Knowledge of Best Practice and security guides (ex. NIST 800-53 rev 4, NIST 800-53, FedRAMP)
- CompTIA Security+.or equivalent certification
Additional Information
Qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, sexual orientation, gender identity, disability or protected veteran status.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
