What are the responsibilities and job description for the QA Lead position at Diamondpick?
The team
We are looking for an experienced DevSecOps Engineer to join our team and drive the integration of security practices into our cloud infrastructure and development pipelines.
The role
- Manage and optimize Azure security solutions, including Azure Security Center, Azure Defender, Azure Sentinel, and Azure Key Vault, to ensure a secure cloud environment.
- Implement and manage Azure networking security components such as NSGs, ASGs, and Azure Firewall to safeguard cloud infrastructure and applications.
- Implement security best practices for containers and Kubernetes using Azure Kubernetes Service (AKS) and ensure that containerized applications are securely deployed and managed.
- Utilize Infrastructure as Code (IaC) tools such as Terraform, ARM templates, or Bicep to securely provision and manage Azure resources.
- Set up and configure Azure Monitor, Log Analytics, and Azure Policy to maintain security posture and governance across the cloud infrastructure.
- Ensure the security of CI / CD pipelines by integrating security tools such as static code analysis, vulnerability scanning, and automated testing.
- Automate security tasks, including monitoring, alerting, and remediation, using scripting languages such as PowerShell, Python, or Bash.
- Work with configuration management tools like Ansible or Chef to manage secure configuration and deployment of cloud infrastructure.
- Ensure compliance with security frameworks and standards such as CIS, NIST, and ISO 27001 to meet regulatory and organizational requirements.
- Collaborate with cross-functional teams to identify and mitigate security risks in both cloud and on-premises environments.
- Perform risk assessments and identify potential security threats and vulnerabilities, implementing the necessary remediation strategies.
- Contribute to continuous improvement of security practices by reviewing and evolving the security posture based on emerging threats and best practices.
- Provide technical expertise and support for security incident investigations, root cause analysis, and remediation.
What you'll bring