Job descriptionDevSecOps Architect
This DevSecOps Architect will be responsible for overall design and direction of eCommerce Security Engineering across all of our applications.
This role is critical in the development and on-going security posture for digital commerce applications.
Accountable for identifying and implementing our security principles and best practices to maintain application security and address the impact of non-human HTTP traffic on both the performance and security of the application by applying blocks, rate limits, tarpits, or other remediation.
This role will focus on partnering with the Security Team on Vulnerability Scanning, will manage SSL certificates, assist with cloud architecture IAM needs, create processes for analyzing web traffic to identify patterns of abuse on the website, provide guidance and/or implement mitigation to address discovered abuse patterns using modern security tools, and work with developers and performance engineers to assist in securing the solution. As a subject matter expert, this role will leverage various monitoring tools to analyze the security posture of both systems & applications while working independently and collaboratively to address any issues discovered.
Through collaboration with software development and platform engineers, threat models will be reviewed and and corresponding mitigation policies will be applied. This role will be accountable to protect all external endpoints to the application stack and facilitate vulnerability scans/remediation.
- Create, maintain, and support security configurations designed specifically for all customer-facing digital applications
- Responsible for Web Application Security: Engineering, deployment, and operations of security policies with for web and security applications, frameworks and designs
- Create automation for security implementations and workflow integrations, including API Security, Container Security, and Cloud Security
- Responsible for Security Software Development: Scripting and Development in Terraform, Bash, Python, or other Shell scripting and development in other languages
- Create and maintain advanced alerts, dashboards, and reports that appropriately monitor for web application attacks and assist with mitigation
- Collaborate with key stakeholders within Security and Engineering teams to continuously improve the application's security posture.
- Collaborate with Business Directors, Managers, and Stakeholders to define expectations including needed security requirements
- Assess and provide technical direction on future projects and needs
- Create and present Solution Architecture designs that reflect security best practices
- Provide accurate and thorough estimates of time and resources necessary to complete security efforts
- Provide guidance to senior technology leadership
- Take part in the full software development lifecycle (SDLC): design, development, testing, deployment, and maintaining
- In all phases of the SDLC, able to engage and provide recommendations to experts of cross functional disciplines
- Coach and mentor developers
- Four-year degree in Computer Science or an equivalent combination of course work and job experience
- 10+ years of experience as a technical security engineer overseeing enterprise or retail level applications – preferably in an agile environment developing highly available software
- 5+ years of experience in DevSecOps working with developers and engineering teams in a dynamic environment to promote/implement DevSecOps throughout the organization
- Strong understanding of retail domain and ecommerce design ond operational processes
- Experience developing and maintaining architecture-based documentation
- Knowledge of open source and commercial application security tools and frameworks
- Experience with modern security and defense mechanism applications
- Experience in exploting web apps and providing guidance on web services security vulnerabilities: cross site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks
- Expert knowledge of DDos techniques, OWASP risks, Vulnerabilities, and Mitigation Mechanisms
- Proficiency in common network and web protocols
- Experience working in cloud environments and understanding of cloud infrastructure (Google Cloud or Amazon)
- Experience with automated continuous integration and continuous deployment software pipelines
- Experience working with on-site and off-site development teams, coordinating work, expectations, and delivery
- Possesses and demonstrates curiosity
- Demonstrates excellent communication skills to both technical and non-technical personnel
- Possess the art of negotiation to drive to end state needs
- Ability to clearly articulate and drive alignment across mutliple teams and departments
- Ability to create and describe project estimations with assumptions and risks
- Ability to work in a fast-paced environment while managing multiple responsibilities
- Willingness to learn new technologies
- Executes with limited to no supervision; self-motivated and self-directed