Risk Consulting - Senior - DevSecOps
ey
Job Description
Your key responsibilities
- Architect, deploy, and manage complex services on one or more major cloud platforms (AWS, Azure, GCP), optimizing cloud resources for performance and cost-efficiency.
- Design, implement, and manage scalable and resilient cloud infrastructure using Terraform, developing reusable infrastructure modules and ensuring consistent deployment across environments.
- Possess strong hands-on experience in deploying, configuring, and troubleshooting Kubernetes environments (on-premise/cloud), and experience in deploying and scaling microservices applications on K8s clusters.
- Implement and manage security best practices for cloud infrastructure and applications, embedding DevSecOps principles.
- Possess strong hands-on experience on configuration management tools (Ansible, Puppet, Chef, etc.).
- Lead and architect large-scale cloud migration initiatives, including re-platforming and re-architecting applications.
- Design and execute strategies for upgrading existing infrastructure, platforms, and applications with minimal downtime and risk.
- Contribute significantly to Responses for Proposals (RFPs) and Requests for Information (RFIs), articulating technical solutions and value propositions.
- Provide expert guidance and solutioning, leading technical discussions with various stakeholders, business groups, and senior leadership.
- Mentor and lead a team of DevOps engineers, fostering their technical growth and ensuring adherence to architectural standards.
Skills and attributes for success
- Experienced in information technology/security risk management or risk consulting.
- Proven experience conducting risk assessments, spot checks, and thematic reviews in a complex, regulated environment.
- Familiarity with IT governance frameworks, secure architecture principles, SDLC and regulatory expectations (e.g. ISO27001, NIST, OWASP).
- Practical understanding of modern IT environments, including cloud platforms (Azure, AWS, GCP, OCI) and enterprise technologies such as Microsoft 365.
- Exposure to risk considerations across software development, platform engineering, or infrastructure is highly valued.
- Familiarity with DevSecOps and secure CI/CD practices in Cloud
To qualify for the role, you must have
- 4 - 9 years of overall work experience in IT
- Knowledge of, and experience with DevSecOps concepts
- Knowledge and experience with Agile practices and tools
- Experience in the technical areas of:
- Python - intermediate
- CI/CD stack - intermediate
- SQL - intermediate
- Terminal/CLI - intermediate
- Terraform - intermediate
- Config management - intermediate
- Container management (EKS/docker) - intermediate
- ITIL - intermediate
- Infrastructure paradigm - SaaS/PaaS/IaaS
- Excellent communication skills with consulting experience preferred
- A valid passport for travel.