Security Controls Engineer
Indexed description
- Design and develop custom security controls based on threat modelling outputs
- Build:
- Detective controls using Python-based frameworks
- Preventative controls using OPA/Rego policies
- Extend and enhance existing security control frameworks
- Develop and maintain:
- Automated unit tests
- Behavioral (BDD) test cases
- Integrate controls into CI/CD pipelines for continuous validation
- Collaborate with:
- Threat modeling teams
- Cloud architects
- Security SMEs
Security Experience Is Required, But Coding Proficiency Is Mandatory.
- Minimum of 3-5 years of experience in DevSecOps engineering with a focus on cloud environments (AWS, GCP, Azure), ideally working within a security program.
- Strong software engineering background - proficiency in software testing methodologies and tools.
- Advanced proficiency in Python - proficiency with Python and Terraform for testing, automation and custom tool development.
- Proficiency with:
- API integrations and backend development
- Writing scalable, maintainable code
- Hands-on experience with:
- Automated testing frameworks (Python)
- CI/CD pipelines
- Experience with cloud-native development and architecture, leveraging services and tools specific to AWS, GCP, and Azure.
- Experience with detection engineering: detection-as-code practices, developing and maintaining detection rules
- Hands-on experience with Open Policy Agency (OPA) for policy enforcement
- Proficiency in DevOps tools and practices
- Experience with SIEM query languages such as Splunk SPL, YARA rules, etc.
- MUST pass Karat Assessment (Python focused).
Qualifications: BACHELOR OF COMPUTER SCIENCE
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search