Senior DevSecOps Engineer
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Responsibilities
- Simplify automation that applies security inter-workings with CI/CD pipelines.
- Work to consistently learn and share advanced skills and practices that promote team excellence.
- Build relationships with developers, stakeholders and scrum master's to incorporate security principles into engineering design and deployments.
- Supervise testing and validation in application security controls across projects.
- Oversee implementation of defensive practices and countermeasures across infrastructure and applications.
- Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads.
- Serve as a point of contact for security-based escalations and remain tightly involved through resolution.
- Build services and tools to enable developers and engineers to easily use security components produced by Application Security team members.
- Support the ability to "shift left" and incorporate security early on and throughout the development lifecycle.
- Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business, and gain support through influential messaging.
- Leverage Vulnerability database sources to understand the weakness, probability and remediation options supplied by vendors as well as workarounds.
- Join forces and provision security principles in architecture, infrastructure and code.
- Regularly research and learn new tactics, techniques and procedures (TTPs) in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary through the CI/CD pipeline.
- Enrich DevOps architecture with security standards and best practices.
- Partner with teams to define key performance indicators (KPIs) and metrics across business units.
- "I am the person Capital Group is looking for"
- Bachelor's degree in Computer Science or related field and/or at least 7+ years' experience in information technology, information security administration or security operations.
- Experience with agile workflows, including Scrum and Kanban.
- Hands-on experience of containers (e.g., Docker) and container orchestration (e.g., Docke
Benefits
Additional Information
"I can be myself at work." You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace. We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community. "I can influence my income." You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses. "I can lead a full life." You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success. Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love Access on-demand professional development resources that allow you to hone existing skills and learn new ones "I can succeed as a Senior DevSecOps Engineer at Capital Group." As a Senior DevSecOps Engineer within the Application Security team, you'll support, secure, manage and deploy solutions that secure the software delivery lifecycle for enterprise applications. This is a highly technical role, so you will need a strong understanding of automation, CI/CD infrastructure, software development, and cloud services. Knowledge of information security and application security tools is highly desirable. The DevSecOps engineer supports the security of continuous integration and continuous deployment (CI/CD) initiatives and is an integrated team member working with software developers, system engineers, cybersecurity engineers and systems administrators. The role is security-focused and helps CI/CD pipelines deliver secure software in a scalable manner while showing developer empathy and engineering excellence such as obsession with security tool output quality, false positive removal, using data / metrics to improve tools that integrate into the CI/CD pipeline. This role is hybrid (in-office 3 days/week) in New York NY.
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at capgroup? Share your experience