Do you enjoy solving advanced technical problems, and working with best in class security tools? Yearn for the opportunity to build a world class application security testing organization? Enjoy building and maintaining successful relationships through direct interaction with peers, managers, and other technical teams? Partnering with management to build a collaborative working environment while promoting high standards, exercising good judgment and professionalism? If you do, then its sounds like you are just the person we are looking for to join our Information Security Team at Delta Air Lines.
The successful candidate can enable DevSecOps practices to enable the enterprise to adopt Development & DevSecOps practices through the building, administration, support of modern development tools and enablement of Delta’s cloud journey and apply secure coding best practices to assist in identifying application vulnerabilities. As an engineer your responsibilities will include, code reviews, container security, and manual API testing. tical to the availability and resilience of the developer happiness and productivity. This team member will also participate in leading and facilitating educational sessions on the use of DevSecOps tools and Cloud Native best practices. Experience implementing, deploying, and providing support for custom AWS Config Rules, CFN Hooks and CFN Guard Rules. Comfortable building and supporting applications in the Cloud (AWS, Azure, GCP). Competence engineering software within an Amazon Web Services (AWS) cloud infrastructure. Experience integrating Open-source controls and tools into current enterprise architecture. Have experience reviewing Open-source components to making recommendations to configuration or environmental changes that increase security or reduce risk. Candidate must be solutions oriented, using rigorous logic and methods to solve difficult problems with effective solutions, probing all sources for answers. Candidate must be able to deliver clean and reliable code, API design, be comfortable with refactoring, test driven development, design patterns, abstractions, writing documentation, and the complete software development life cycle.
Key Responsibilities:
- Capable of leading projects to implement tools in CICD pipelines to aid in conducting Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode
- Experience working with tools such as Sonatype nexus firewall and lifecycle to track and block risk 3rd- party components
- Work within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines
- Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.
- Guide development teams in integrating new services and applications into the CI/CD pipeline, troubleshoot installations and build automated deployments of products into a high-security architecture.
- Extensive knowledge of CI tools such as Jenkins, Tekton, CircleCI, GitlabCI, AWS Code Pipeline etc.
- Test driven mindset with experience in automation with development tools
- Comfortable with facilitating training on enterprise tools and best practices
- Collaborate with and across Agile teams to design, develop, test, implement, and support technical solutions in full-stack development tools and technologies
- Apply software development skills (e.g., Java, C.NET, JavaScript) to recommend and apply secure coding practices
- Utilize programming languages like JavaScript, Java, HTML/CSS, TypeScript, SQL, Python, and Go, Open-Source RDBMS and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of AWS tools and services
- Knowledge of secure coding standards.
- Experience with Agile methodologies.
- Experience with AWS and Kubernetes
- Experience in working with 12-factor methodology and understanding its benefits, and able to demonstrate appropriate patterns to other team members Develops and presents finding and remediation reports to audiences including team members from all department areas and levels of the company
- Consult with development Teams to perform security reviews of software designs and assist developers to ensure quality and robustness of our internal products
- Conduct security assessments against web applications and APIs across a variety of technology stacks
- Performs technical design reviews and code reviews.
- Ensure adequate security requirements and privacy by design are built into all architecture/infrastructure/projects
- Drive improvements in the security testing practice to include execution methodology and metrics
- Drive awareness and knowledge of security in the developer community
- Continually improve proficiency in application and API exploitation, tools, techniques, and countermeasures
- Expertise in software development: clean and reliable code, API design, refactoring, test driven development, design patterns, abstractions, writing documentation, and the complete software development life cycle.