Responsibilities:
- Write and maintain IaC scripts (e.g., using tools like Terraform, AWS Cloud Formation) to provision and configure cloud resources securely.
- Optimize CI/CD workflows for security by automating testing and security scans at every stage of the pipeline.
- Implement and manage IAM roles and permissions for cloud resources, adhering to the principle of least privilege.
- Configure and manage security-related monitoring tools and log management systems to detect and respond to security incidents.
- Ensure that cloud infrastructure and applications comply with industry-specific regulations and internal security policies
- Prepare for and participate in security audits.
- Maintain documentation for security configurations, procedures, and best practices for the DevOps team and auditors.
- Continuously optimize cloud infrastructure for performance, cost, and security.
- Collaborate with cross-functional teams, including developers, system administrators, and security professionals, to align security goals with development and operations.
Required Skills:
Education Requirement: Bachelor's or Master's degrees in Computer Science, Information Science, Electrical Engineering, or their foreign equivalents in education.
Certifications: Possession of industry-recognized certifications such as CompTIA Security+, Certified Information Systems Security Professional (CISSP), etc.
Experience:
- Experience: Minimum 5 Years of Experience (with a bachelors degree) working within an IT environment. 3 years of additional relevant experience may be substituted for a degree for a total of at least 8 years of work experience
- Knowledge of infrastructure as code (Terraform, Ansible, Cloud Formation) and configuration management tools.
- Strong knowledge of security principles, protocols, and best practices.
- Familiarity with CI/CD tools, containerization (Docker), orchestration (Kubernetes), security tools and technologies (e.g., SIEM, IDS/IPS, firewalls, encryption).
- Excellent problem-solving skills and the ability to analyze complex systems and networks