Company:
MMC CorporateDescription:
Marsh McLennan is seeking candidates for the following position. This role will be based in Canada. This is a hybrid role that has a requirement of working at least three days a week in the office.
Join our dynamic team as a DevSecOps & Secure-SDLC Engineer, where you will play a pivotal role in leading initiatives that enhance our Secure Software Development Lifecycle (Secure-SDLC) in alignment with our Application Development Security Policy. In this position, you will be responsible for selecting and standardizing application security tools through comprehensive vendor assessments and proof of concepts. You will integrate Secure-SDLC requirements into our DevSecOps processes, ensuring that our application security standards are robust and tailored for agile development methods across both traditional and cloud architectures, including container workloads.
DevSecOps & Secure-SDLC Engineer
We will count on you to:
Advise the application security leadership on best practices and standards around application security tools with main focus on shift-left, create predictable CI/CD pipeline processes, and enable application teams to develop new capabilities securely, and free from security defects, by design
Assess security tools and related processes currently used within the various Software Development Life Cycle processes to identify improvements opportunities, and rationalize the tools set
Select new application security tools including vendor/tool assessments and conduct full POC to prove that the security solutions/products are fit-for-purpose and fit-for-use
Draft documentations for the Secure-SDLC and DevSecOps to illustrate the frameworks and its process guidelines to internal customers ensuring the style is palatable and easy to navigate
Assess impact of new publications from the security industry (e.g. NIST 800-XXX, ISO 2700X:2022, etc) on the company’s AppSec programs
Research new trends and advise the application security leaderships on impact of the new trends as they relate to currently used tools, tool chain roadmap, efficiency and effectiveness of current processes, etc.
Promote secure coding standard and all related processes
Promote the priorities set forth by Global Information Security function, and the roadmap set forth by the Global Application Security
Automate and integrate security scan and analysis tools into the DevSecOps pipeline
What you need to have:
5 years+ DevSecOps and Secure-SDLC work experience
CISSP, CSSLP, cloud security, DevSecOps automation, or similar is required
Post-secondary education or equivalent experience as a DevSecOps Engineer
Develop/enhance and implement the Secure-SDLC framework
Design, implement, and rollout DevSecOps automations and tool chain
Implement sensors to collect data on key metrics for statistics and reporting
Serve as the subject matter expert in Secure-SDLC and DevSecOps
Advise on the processes and standards that are designed to implement a company’s Application Development Security Policy
Experience in designing Secure-SDLC processes and relevant tooling to support the processes
Experience in software/application analysis tools like SAST, DAST, SCA, threat modeling, supply-chain etc.
Technical hands-on experience in automating and integrating security scan and analysis tools into the DevSecOps pipeline.
Experience in one or more programming languages
Familiarity with security frameworks (OWASP Top 10, SANS Top 25, CWE)
What makes you stand out:
Identify application security requirements and brainstorm solutions factoring in industry best practices
Assess the tooling and remediation of threats and vulnerabilities within our software/applications, and the hosting environment
Why join our team:
We help you be your best through professional development opportunities, interesting work, and supportive leaders.
We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients, and communities.
Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.
Other Jobs from NERA Economic Consulting
Data Engineer
Kubernetes Platform Engineer
Junior Data Engineer @DARWIN
Senior Data Engineer
Senior Data Engineer
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say