Proven expertise deploying one of the commercial container security products and closing the gaps through development, automation, API integrations, and researching and closing vulnerabilities via patching.
Expertise in SAST and DAST
- Advanced expertise in securing containerized workloads (familiarity with Jenkins, Docker, Kubernetes/OpenShift/ROSA).
- Assist selecting and implementing tools that will elevate the maturity of the DevSecOps practice.
- Identify opportunities for automation, partner with engineering and security teams on implementing automation.
- Develop and support development of security testing and validation tooling.
- Desing and implement container image security lifecycle in CI/CD pipeline covering source control, integration, and deployment (ex:
Bitbucket, Azure DevOps, Tekton, Nexus, OpenShift, ROSA, Red Hat Advanced Cluster Security or equivalent contain).
- Stay abreast of industry trends and best practices; conduct research, tests, and execute recent techniques that can be reused and applied to SDLC.
- Proficient with language - python.
- Familiarity with development using RESTful APIs.
- Familiarity with microservice and service mesh architecture.
- Familiarity of advanced iterative Agile methodologies.
- Familiarity to security standards such as NIST 800-53, NIST 800-190 and NIST 800-204A