We are seeking a talented DevOps Security (DevSecOps) professional to join EPAM's Security practice, which is dedicated to serving our renowned clients in the Hospitality and Tourism sector.
In this pivotal role, the successful candidate will be instrumental in integrating and maintaining security measures throughout the application development and deployment processes to uphold and enhance security standards.
#LI-DNI
Responsibilities
- Support the coordination of EPAM, customer, and QSA efforts for PCI annual certification
- Embed security controls within development and deployment pipelines
- Automate security processes to maintain pace with DevOps deployment cycles
- Establish Secure Software Development Lifecycle (SSDLC) programs
- Train software development teams on secure development methodologies and tools
- Review and recommend robust security architecture in AWS
- Communicate the significance of a Secure Software development Life Cycle with customer and teams
- Work across teams - including BAs, TLs, Developers, and QA - ensuring consistent understanding of security requirements and implemented mitigations
- Collaborate and coordinate with other security teams such as Cloud Security Engineers or Penetration Testers
- Conduct risk assessments, identify vulnerabilities and recommend mitigation measures
- Develop and implement incident response plans
- Perform regular code reviews and security tests including both static and dynamic analysis
- Align security activities with business stakeholders and goals
Want more jobs like this?
Get jobs in San Javier, Chile delivered to your inbox every week.
- 2+ years of Software Development or Security-focused experience
- High motivation for development and growth within the security field
- Familiarity with Security Development methodologies (e.g., Microsoft SDL, OWASP OpenSAMM, BSIMM)
- Familiarity with OWASP Top 10 security threats and attack scenarios
- Hands-on experience with Threat Modeling and familiarity with Threat Modeling Tools
- Familiarity with tools for Static Code Analysis, Static / Dynamic Application Security Testing, Penetration Testing, Intrusion Detection / Prevention
- Understanding of core Security-related activities within development including Security Requirements gathering, Risk Assessment, Security Code Review
- Experience with PCI DSS and GDPR security standards and their implementation requirements
- Understanding of main security concepts, principles, areas of protection, levels of defense, threats mitigation mechanisms, and basic principles of infrastructure security and penetration testing
- Proficiency in cloud security controls and policy implementation on AWS
- Fluent English communication skills at a B2+ level
- Knowledge of Security Features and Mechanisms provided by major OS and development platforms/technologies
- Familiarity with DevOps principles such as CI/CD, test automation, shift-left security, and shared responsibility models
- Experience with Microsoft Azure's cloud security controls and policies
- Relevant certifications like CISSP, CCSP, SANS GIAC or similar qualifications are a plus
- Improved medical coverage - EPAMers are eligible to participate in a supplementary health insurance program that shall have the usual coverage in the industry, with the Company funding 100% of the value of the monthly premium for participation
- Lunch Allowance - You will receive a daily allowance of CLP $ 7,000 per working day. Enjoy a nice meal on us
- Allowance for internet and electricity - You will receive an allowance of CLP $15,000 per month to cover internet and electricity expense
- National Holiday Bonus - We celebrate joining the Chilean Market. That is why all our employees will receive a bonus of CLP $86,646 in September
- Christmas Bonus - You will receive an End of Year bonus of CLP $170,539. It will be paid during the month of December, to ensure you have a Happy Holiday!
- Learning Culture - We want you to be the best version of yourself, that is why we offer unlimited access to learning platforms, a wide range of internal courses, and all the knowledge you need to grow professionally
- Additional Income - Besides your regular salary, you will also have the chance to earn extra income by referring talent, being a technical interviewer, and many more ways
- Are you open to relocation? - If you want to relocate to another country and we have the right project, we will assist you every step of the way, to help you and your family, reach your new home