All jobs
Charles RiverDevOps
Senior InfoSec Engineer (SecDevOps)
IndiaPosted today
The Senior InfoSec Engineer (SecDevOps) at Charles River is a remote role based in India, focusing on integrating security into DevOps practices, assessing cybersecurity risks, and developing secure strategies across projects.
Location: India
Responsibilities
- Develop, implement, and maintain secure CI/CD pipelines to facilitate safe code releases without sacrificing speed or efficiency.
- Collaborate with development and operations teams to integrate security at every phase of the software development lifecycle.
- Conduct vulnerability assessments and security tests on applications and infrastructure to identify and mitigate risks before production deployment.
- Automate security processes to reduce human error and increase incident response times.
- Maintain security documentation and standard operating procedures.
- Stay up to date with emerging security threats and vulnerabilities and ensure that the company's systems and data are protected against them.
- Provide security awareness training to other teams and advocate for security best practices throughout the organization.
- Participate in the development and enforcement of security policies and procedures.
- Perform other duties as assigned.
Requirements
- Bachelor’s degree (B.A./B.S.) or equivalent in computer science, information security, or related discipline.
- 3+ years of experience in a DevOps role with a strong focus on security, or in a dedicated cybersecurity role with exposure to DevOps practices.
- An equivalent combination of education and experience may be accepted as a satisfactory substitute for the specific education and experience listed above.
- IT security related certification desired (e.g., CISSP, CISM, CompTIA Security+, Certified Kubernetes Security Specialist (CKS), or AWS Certified DevOps Engineer, or similar professional certification).
- Strong understanding of cloud platforms (AWS, Azure, GCP) and their native security tools.
- Proficiency in scripting languages (e.g., Python, Bash) and automation tools (e.g., Ansible, Terraform, Jenkins).
- Familiarity with containerization and orchestration technologies (Docker, Kubernetes).
- Knowledge of compliance standards and security frameworks (e.g., ISO 27001, NIST, SOC 2).
- Experience with secure software development practices such as using SAST/DAST tools, secure code review, and threat modeling.
- Excellent problem-solving skills and ability to think critically and strategically.
- Effective communication skills, with an ability to convey complex security issues to non-technical stakeholders.
- Must have strong interpersonal, teamwork, self-initiative skills.
Benefits
- bonus/incentives based on performance
- 401K
- paid time off
- stock purchase program
- Health and wellness coverage
- employee and family wellbeing support programs
- work life balance flexibility