DevSecOps Engineer
Casablanca, MA, 20270
IDEMIA
We make it safer and easier for people to pay, connect, be identified, access, travel and stay safe in the physical and digital worlds.
Since our founding, IDEMIA has been on a mission to unlock the world and make it safer through our cutting-edge identity technologies. Our technology leadership makes us the partner of choice for hundreds of governments and thousands of enterprises in over 180 countries, including some of the biggest and most influential brands in the world. In applying our unique expertise in biometrics and cryptography, we enable our clients to unlock simpler and safer ways to pay, connect, access, identify, travel and protect public places – at scale and in total security.
Our teams work from 5 continents and speak 100+ different languages. We strongly believe that our diversity is a key driver of innovation and performance.
Purpose
You will take the role of a DevOps Engineer in the context of DevSecOps and Cyber Security Tasks. You will be part of the IPS Dvision Transverse Cybersecurity team but will be also integrated partly within the DevOps team in order to have the necessary up to date know-how.
Key Missions
Key Responsibility:
- Maintain, support and setup DevSecOps tools and tool-related infrastructure
- Participate in the setup of third party or custom tools related to DevSecOps (general scripting).
- Define, implement and maintain CI/CD (Continuous Integration and Continuous Deployment) architecture and tooling in the context of cybersecurity tooling
- Develop infrastructure to incorporate latest technology best practices, and improve operational performance
- Operate and debug basic integration processes and environments under the guidance of a more experienced DevOps/DevSecOps Engineer
- Participate to the evaluation, review, selection, mapping, and setup of security tooling.
- Monitor, diagnose, report and remediate security issues within the software development platform, as a role of security champion.
Outside of this DevOps scope, you will also have a secondary DevSecOps Analyst role that you will be trained for, with the following responsibilities:
- You will assist, support, and guide project teams in understanding, analyzing, tracking, and remediating vulnerabilities detected by automated tools (e.g. SAST, SCA) and document this process and its conclusions in a formal report.
- You will guide project teams towards using DevSecOps tools and methods, and participate in their implementation, usage deployment, and day-to-day use.
- You will participate to projects aiming to improve the general level of security within the IPS company division, by using your experience and capacity of analysis.
- This may be by documenting and formalizing processes, methods, guides, trainings related to cybersecurity, as well as by driving or participating to cybersecurity-related automation and scripting tasks.
Profile & Other Information
Required Skills:
- Strong Linux knowledge
- Strong CI/CD platform knowledge (Ideally Jenkins, Groovy)
- Scripting (Python; Bash, shell)
- Strong containerization skills (docker)
- Good knowledge of CI tools ecosystem:
- source code repositories
- binary repositories
- containers registries
- automation servers
- code inspection, code quality, code scanning
Important Soft skills:
- Problem solver attitude (ability to drill down to find root causes)
- DevOps practices Reactivity/accountability
- Able to work, learn, and investigate subjects autonomously.
- Good communication skills
- Read, written, and spoken English is mandatory.
Some nice to have skills:
- 2-3 years of experience in a DevOps role
- Good knowledge of Atlassian tools
- Apache tools knowledge: HTTP server, Maven, Groovy
- SW system architecture knowledge
- Java/JEE knowledge
- Zabbix monitoring
- Ansible knowledge
- Experience in the development of applications and knowledge of technologies used in an agile / DevOps environment.
- Good understanding of SAST, SCA and DAST tools to automate the detection of security issues.
- Good understanding of Software development lifecycle in an Agile environment, and you understand DevOps very well.
By choosing to work at IDEMIA, you will join a unique tech company, offering a wide range of growth opportunities. You will contribute to a safer world, collaborating with an international and global community. We value the diversity of our teams and welcome people from all walks of life, regardless of how they look, where they come from, who they love, or what they think.
We deliver cutting edge, future proof innovation that reach the highest technological standards and we’re transforming, fast, to stay a leader in a world that’s changing fast, too.
At IDEMIA, people can develop their expertise and feel a sense of ownership and empowerment, in a global environment, as part of a company with the ambition and the ability to change the world.
Visit our website to know more about the leader in Identity Technologies
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Ansible Automation Bash CI/CD Cryptography DAST DevOps DevSecOps Docker IPS Java Jenkins Linux Maven Monitoring Python SAST Scripting SDLC Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.