DevSecOps Engineer, you will serve as a security partner to multiple product teams, helping them build and maintain secure AWS infrastructure while ensuring compliance with industry standards.
You'll be responsible for vulnerability management, threat mitigation through Akamai WAF/CDN, and providing security guidance throughout the product development lifecycle.
Top Skils:
AWS, Akamai or Cloudflare
GitLab, GitHub or equivalent: Experience with GitLab CI/CD security features, scanning tools, and workflow management
Programming: Strong skills in Python, Go, and Bash for automation and tooling development
Skilled in reverse engineering
Demonstrates critical thinking
AWS:
Have you integrated AWS security services (CloudTrail, GuardDuty, Security Hub, Config) with a SIEM platform (Splunk, Datadog, Elastic, Sumo Logic), created custom detection rules and correlation alerts, and built dashboards for security operations teams?
Have you used IAM Access Advisor, CloudTrail logs, or third-party tools to analyze unused permissions and implement least-privilege policies?
Have you systematically removed unused permissions from production roles based on actual usage patterns?
AKAMAI:
Have you created custom WAF rules for your specific hostname to address unique application security requirements, using conditions like specific headers, request body patterns, or custom rate limits?
Have you monitored WAF security events for your specific hostname using Akamai's Security Dashboard or SIEM integration, investigated blocked requests to determine if they were legitimate or attacks, and made configuration adjustments based on attack patterns?
Technical Expertise:
AWS Platform: 3+ years of hands-on experience securing enterprise level AWS environments and services
Kubernetes: Proficiency in Kubernetes security, EKS configuration, and container security best practices
Monitoring Tools: Hands-on experience with Datadog and/or Splunk for security monitoring and alerting
Akamai Platform: Experience with Akamai WAF, CDN security configurations, and threat mitigation
Infrastructure as Code: Advanced knowledge of Terraform, CloudFormation, Ansible
AWS Security Services: Experience with GuardDuty, Security Hub, Config, Inspector, IAM, and CloudTrail