Tech Stack
AzureCloudCyber SecurityDockerKubernetesPythonTerraformVault
About the role
- Design, implement, and maintain secure cloud infrastructure using Microsoft Azure services and Infrastructure as Code (IaC) practices
- Develop and maintain CI/CD pipelines with integrated security controls using GitLab CI and other automation tools
- Deploy and manage containerized applications using Docker, Kubernetes, and Azure Kubernetes Service (AKS) with security best practices
- Configure and manage security tools including SAST/DAST scanners, vulnerability scanners, IDS, and SIEM systems, with emphasis on Azure-native security tooling
- Implement and maintain Azure security services including Azure Security Center, Azure Sentinel, Azure AD, Azure Key Vault, NSGs, Azure Firewall, and Azure Policy
- Automate security processes and infrastructure provisioning using Terraform, Azure Resource Manager (ARM) templates, and scripting languages
- Manage artifact repositories using JFrog Artifactory and maintain secure development environments
- Configure and deploy AI/ML solutions and Large Language Model (LLM) systems within secure environments
- Collaborate with development teams to integrate security practices into Agile development processes
- Monitor and respond to security incidents while maintaining operational support capabilities
Requirements
- U.S. Citizenship and interim secret security clearance
- At least Interim Secret Clearance required
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent experience
- 3+ years of experience in DevSecOps, cloud security, or related roles
- Strong understanding of security principles, technologies, and best practices
- Expertise in Microsoft Azure and its security services
- Experience with containerization technologies (Docker, Kubernetes, Azure Kubernetes Service) and container security best practices
- Extensive experience with Terraform and Azure Resource Manager (ARM) templates for Infrastructure as Code (IaC)
- Experience with security tools such as SAST/DAST scanners, vulnerability scanners, intrusion detection systems, and SIEM systems
- Proficiency in scripting languages (Python, Bash, PowerShell) and automation tools
- Experience with CI/CD pipelines (GitLab CI) and integrating security into the pipeline