This job has expired.
Quadrant Resource
Expired

Infrastructure Security analyst/Security Engineer(DevOps) (Remote)

Remote

Location restricted
This job is restricted to tax residents of , but we detected your IP as outside of the country. Please only apply if you are a tax resident.

Role: Infrastructure Security analyst/Security Engineer(DevOps)

Position: US, but can work remotely

Job Description:

  • Candidate should have a software engineering background with strong security and compliance experience
  • Familiarity with code-level security (crypto, hacking, DAST on continuous integration, CI/CD tool protection),  infrastructure security (SSL/TSL, SSH, Container protection), Protection of data and information (two-factor authentication, compliance with industry standards, public security policy, denial of service, breaches, server and infrastructure),  monitoring of threats and vulnerabilities (auditing infrastructure, TLS certification expiry, detect incident threats, app attacks, monitor third-party vendors, monitor authorizations, monitor DNS expiry)
  • Security consultant should be able to assist in creating and maintaining documents, processes, standards for  1) identify critical information and sensitive data, 2) identify the possible threat, 3) assess vulnerabilities and analyze security vulnerabilities, 4) analyze the risk associated with each vulnerability, 5) develop and apply countermeasures.
  • Experience with Cybersecurity software, threat modeling, and security risk assessments to detect and analyze security threats
  • Up-to-date knowledge of cybersecurity threats, current best practices, and latest software.
  • Experience with infrastructure Audit which is auditing of servers, network devices, services exposed etc
  • Familiar with OWASP, Dynamic application security testing (DAST) in continuous integration, Static application security testing (SAST), SSL/TLS scanning, SSH configurations,  DNS 
  • Exposure to one or more programs such as Puppet, Chef, ThreatModeler, Checkmarx, Immunio, and Aqua. 
  • Understanding or experience with Kubernetes, Docker, or AWS. Familiarity with container protection, security, and vulnerabilities
  • Source code management and password encryption, two-factor authentications
  • Auditing or/and Documenting security standards and practices such as GDPR, HIPPA 
  • Secure SDLC framework (scrum, hybrid)
  • OWASP (open web application security project) – code security scanning software
  • Security requirements – GDPR, HIPPA, PIPA (PHI, PII) – other security certifications
  • Industry application security best practices?
  • Coding practices for Input validation, authentication and authorization
  • Secure coding cryptography (data in rest, HTTPS, archive and log practices, in memory practices)
  • AWS – Algorithms e.g. black box.

Job Types: Full-time, Contract

Experience:

  • AWS: 2 years (Required)
  • Security Engineering: 5 years (Required)
  • threat modeling: 1 year (Preferred)
  • Cybersecurity software: 1 year (Preferred)
  • DevOps: 5 years (Required)
  • Compliance: 2 years (Required)
  • security risk assessments: 1 year (Preferred)

Work Remotely:

  • Yes

Other DevOps contracts

Remote
0
USD
/hr

0 outside IR35 DevOps contracts