DevSecOps Subject Matter Expert
hpe `
Job Description
- DevSecOps Strategy & Implementation
- Define and implement DevSecOps best practices, embedding security into every stage of the SDLC.
- Integrate security tools, processes, and automation into CI/CD pipelines.
- Champion a “shift-left” approach to security in development and deployment workflows.
- Security Automation & Tooling
- Deploy and manage SAST, DAST, SCA, and container scanning tools within CI/CD environments.
- Automate security testing, compliance checks, and vulnerability management.
- Implement Infrastructure as Code (IaC) security scanning and remediation.
- Pipeline & Cloud Security
- Design secure, automated build and deployment pipelines for multi-cloud and hybrid environments.
- Ensure cloud security posture management (CSPM) and compliance monitoring are integrated into operations.
- Collaboration & Governance
- Partner with development, QA, operations, and security teams to ensure secure code delivery.
- Define and enforce security policies, standards, and guidelines.
- Provide technical guidance and mentorship on secure coding and DevSecOps practices.
- Monitoring, Incident Response & Continuous Improvement
- Monitor application and infrastructure security in real time, leveraging SIEM/SOAR integrations.
- Participate in incident response and post-mortem analysis for security-related issues.
- Continuously assess and improve DevSecOps processes, tools, and culture.