As a Senior Security Engineer, you will play a vital role in ensuring that Veryfi's infrastructure and applications meet high security standards and helping with meeting various compliance requirements.
Your primary goals will be ensuring that systems are patched and vulnerabilities remediated within assigned timeframes, setting up tools and defining processes to ensure high security standards and compliance requirements are met, developing automated processes to monitor and report on security posture of Veryfi's systems.
Key Responsibilities:
- Remediate vulnerabilities independently and in collaboration with engineering and operations teams
- Design and develop automated processes for monitoring and reporting on the security posture of systems
- Configure security scan tools (SAST, DAST, etc) and implement their use in CI/CD pipelines
- Design and configure security measures in cloud-based infrastructure
- Carry out regular internal audits and appropriateness reviews
- Help drive a security-first culture in the company
Skill Requirements:
- High level of proficiency administering AWS cloud services such as IAM, AWS Inspector, CloudTrail, GuardDuty, AWS Config, EC2, WAF, VPC, network configuration, etc
- High level of proficiency identifying and remediating vulnerabilities using tools like AWS Inspector, SonarQube, OWASP ZAP
- Proficiency in Linux administration, shell/bash scripting
- Working knowledge and experience with CI/CD tools like Jenkins, GitHub/GitLab pipelines and containerization tools like Docker
- Working knowledge and hands-on experience with compliance frameworks like SOC2, ISO27001, NIST, FedRAMP, FISMA
Prior Experience:
- 5+ years administering AWS cloud services such as IAM, AWS Inspector, CloudTrail, GuardDuty, AWS Config, EC2, WAF, VPC, network configuration, etc
- 5+ years administering Linux servers, including shell/bash scripting
- 3+ years maintaining implementation of security controls outlined by compliance frameworks like SOC2, ISO27001, NIST, FedRAMP, FISMA
- 3+ years administering SAST + DAST tools like SonarQube, OWASP ZAP or similar
- 3+ years identifying and remediating vulnerabilities using tools like AWS Inspector, Clair, or similar
- 3+ years CI/CD (Jenkins, GitHub/GitLab pipelines) and Docker
- 3+ years experience with Python
- 3+ years experience with CarbonBlack and VMWare UEM is highly regarded