02 Aug
|
Daimler Truck
|
Bengaluru
02 Aug
Daimler Truck
Bengaluru
We are seeking a motivated candidate to join our dynamic security team. The ideal candidate will have a robust background in managing Snyk, conducting code reviews, hands-on coding, and experience with Kubernetes, FOSS (Free and Open Source Software), and Black Duck. This role is crucial for ensuring the security and integrity of our software development lifecycle.
Key Responsibilities:
1. Snyk Management:
- Configure, maintain, and optimize Snyk within the organization to identify and remediate vulnerabilities in dependencies and code.
- Develop and enforce Snyk policies and best practices.
- Provide training and support to development teams on using Snyk effectively.
- Code Review:
- Perform thorough code reviews to identify security vulnerabilities and provide actionable feedback.
- Establish and maintain code review guidelines and standards.
- Collaborate with developers to ensure secure coding practices are followed.
- Hands-On Coding:
- Engage in hands-on coding to demonstrate secure coding practices and provide examples.
- Contribute to the development of security-related tools and scripts.
- Assist in the implementation of security features within applications.
- Kubernetes Security:
- Ensure the secure deployment and management of applications in Kubernetes environments.
- Implement security best practices for Kubernetes clusters, including namespaces, RBAC, and network policies.
- Monitor and respond to security incidents within Kubernetes environments.
- FOSS Management:
- Manage the use of FOSS within the organization,
ensuring compliance with licenses and security standards.
- Conduct regular audits of FOSS components for vulnerabilities and license compliance.
- Collaborate with legal and procurement teams to mitigate risks associated with FOSS.
- Black Duck Integration:
- Integrate and manage Black Duck within the development pipeline to identify and manage open source vulnerabilities.
- Generate and analyze reports on open source usage and vulnerabilities.
- Work with development teams to remediate identified vulnerabilities.
- Security Advocacy:
- Promote a culture of security awareness within the organization.
- Conduct training sessions and workshops on security topics.
- Stay current with emerging threats and security trends, and advocate for appropriate changes within the organization.
- Education: Bachelor’s degree in Computer Science, Information Security, or a related field.
- Experience: 2-5 years of experience in a similar role, with a focus on SAST tools and practices.
- Technical Skills:
- Proficiency in Snyk, Black Duck, and other SAST tools.
- Strong understanding of secure coding practices and principles.
- Experience with Kubernetes and container orchestration.
- Knowledge of FOSS licenses and management.
- Familiarity with CI/CD pipelines and integration of security tools.
- Soft Skills:
- Excellent communication and interpersonal skills.
- Ability to work collaboratively with development and operations teams.
- Strong problem-solving skills and attention to detail.
📌 DTICI_SAST_ (Bengaluru)
🏢 Daimler Truck
📍 Bengaluru