M1 - IT Security Lead – DevSecOps
SILMC - SERVICIOS INTEGRADOS DE LEALTAD, MERCADOTECNIA Y COMUNICACIÓN, S.A.P.I. DE C.V.
Digital@FEMSA
FEMSA es una empresa que genera valor económico y social por medio de empresas e instituciones y busca ser el mejor empleador y vecino de las comunidades en donde tiene presencia.Job Family: Technology > Sub-family: Cybersecurity
Reports to (role): CTSO Manager
Objective of the Role
As the IT Security Lead – DevSecOps, you will be responsible for leading the DevSecOps practice within our tech product development team. This role involves overseeing the integration of security into the DevOps processes, ensuring the secure development, deployment, and operation of our applications and infrastructure. You will collaborate with development, operations, and security teams to drive a culture of security automation and continuous improvement.
Main Responsibilities
- Lead and mentor a team of DevSecOps engineers, fostering a collaborative and innovative work environment.
- Develop and implement a comprehensive DevSecOps strategy that aligns with the company's business objectives.
- Integrate security practices into the CI/CD pipelines to ensure secure code deployment and infrastructure provisioning.
- Implement and manage security tools and platforms such as static code analysis, dynamic application security testing, and container security.
- Automate security processes to enhance efficiency and reduce manual intervention.
- Monitor and respond to security incidents related to the development and deployment processes.
- Conduct security assessments and code reviews to identify vulnerabilities and ensure compliance with security standards.
- Collaborate with development, operations, and security teams to ensure security is embedded throughout the software development lifecycle.
- Provide training and guidance to team members on DevSecOps best practices and emerging security threats.
- Stay updated on the latest trends and advancements in DevSecOps and security automation technologies.
- Drive innovation by exploring new tools, techniques, and best practices to enhance the DevSecOps practice.
- Communicate effectively with stakeholders to ensure awareness and understanding of DevSecOps initiatives and their impact.
- Develop and maintain documentation on DevSecOps processes, tools, and best practices.
- Ensure compliance with industry standards and regulatory requirements related to DevSecOps.
- Participate in incident response activities and conduct root cause analysis for major incidents.
- Foster a culture of continuous improvement and proactive problem-solving within the DevSecOps team.
- Promote an autonomous work culture by encouraging self-management, accountability, and proactive problem-solving among team members.
- Serve as a Spin Culture Ambassador to foster and maintain a positive, inclusive, and dynamic work environment that aligns with the company's values and culture.
Required Knowledge and Experience
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Extensive experience in DevSecOps, cybersecurity, and information security within a technology-driven environment.
- Proven experience in leading and managing a team of engineers.
- Strong understanding of DevSecOps tools and platforms, such as Jenkins, GitLab, Docker, Kubernetes, SonarQube, etc.
- Experience with cloud environments (AWS, Azure, GCP) and container orchestration (Kubernetes, Docker).
- Proficiency in scripting and automation using languages such as Python, Bash, or similar.
- Excellent analytical and problem-solving skills.
- Strong communication and collaboration skills to work with cross-functional teams.
- Self-management skills to ensure task and objective completion.
- In-depth knowledge of software development practices and DevOps principles.
- Familiarity with security frameworks and standards relevant to DevSecOps.
- Advanced English proficiency.
Spin está comprometida con un lugar de trabajo diverso e inclusivo.
Somos un empleador que ofrece igualdad de oportunidades y no discrimina por motivos de raza, origen nacional, género, identidad de género, orientación sexual, discapacidad, edad u otra condición legalmente protegida.
Si desea solicitar una adaptación, notifique a su Reclutador.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Automation AWS Azure Bash CI/CD Cloud Code analysis Compliance Computer Science DAST DevOps DevSecOps Docker GCP GitLab Incident response Jenkins Kubernetes Python Scripting SDLC Security assessment SonarQube Strategy Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.