- Drive the evolution of the company’s DevSecOps function by defining security initiatives, long-term priorities, and promoting a security-first engineering mindset.
- Partner with the DevOps team to improve the security and resilience of Kubernetes (EKS), Istio, Service Mesh, and related cloud-native infrastructure.
- Support engineering teams during service transitions by embedding security best practices into operational processes and ensuring effective knowledge sharing.
- Develop and maintain policy-as-code frameworks and infrastructure validation mechanisms using technologies such as OPA and other compliance automation tools.
- Improve the security of infrastructure provisioning and deployment workflows across Terraform, Ansible, and other Infrastructure-as-Code solutions.
- Integrate, maintain, and optimise security testing and scanning capabilities throughout the software development and release lifecycle.
- Build automation around security monitoring, compliance checks, and operational controls to increase efficiency and reduce manual effort.
AWSGitKubernetes+3 more