Job Overview
SAIC is seeking a highly skilled DevSecOps Engineer to join our dynamic team in Huntsville, Alabama. In this role, you will be at the forefront of integrating security practices into our development and operations pipelines, ensuring that our systems are both secure and efficient. You will collaborate with cross-functional teams to design, implement, and maintain automated security controls, fostering a culture of security-first development.
Key Responsibilities
- Integrate Security into CI/CD Pipelines: Design and implement automated security testing, vulnerability scanning, and compliance checks within continuous integration and continuous delivery (CI/CD) pipelines.
- Implement Security Controls: Deploy and manage security tools such as static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) to identify and remediate vulnerabilities.
- Automate Infrastructure Security: Utilize infrastructure-as-code (IaC) tools like Terraform, Ansible, or CloudFormation to enforce security policies and automate the provisioning of secure environments.
- Monitor and Respond to Threats: Set up monitoring, logging, and alerting systems (e.g., Splunk, ELK Stack) to detect and respond to security incidents in real-time.
- Collaborate with Development Teams: Work closely with developers to embed security best practices into the software development lifecycle, from design through deployment.
- Conduct Security Assessments: Perform regular security assessments, penetration testing, and code reviews to identify and mitigate risks.
- Maintain Compliance: Ensure that systems meet industry standards and regulatory requirements (e.g., NIST, FedRAMP, SOC 2).
- Document Processes: Create and maintain documentation for security policies, procedures, and incident response plans.