Job Description
Xometry is seeking a Staff DevSecOps Engineer to enhance its security posture. The ideal candidate will have 5+ years of experience in DevSecOps or related fields, with a focus on integrating security into the software development lifecycle.He/she will work closely with development, operations, and security teams to embed security into the CI/CD pipeline. The DevSecOps Engineer will design, implement, and maintain security automation tools and processes to manage vulnerabilities. He/she will also develop and enforce security policies and conduct security assessments.
Responsibilities: - Collaborate with development, operations, and security teams to integrate security into the CI/CD pipeline.
- Design, implement, and maintain security automation tools.
- Develop and enforce security policies for cloud-based and on-premises infrastructure.
- Monitor and analyze security vulnerabilities and incidents.
- Perform regular security assessments and penetration tests.
- Implement and manage security tools.
- Work with development teams to ensure secure coding practices.
- Lead efforts to secure Kubernetes clusters and containerized environments.
- Manage infrastructure as code (IaC) using tools like Terraform.
- Automate security tasks using Python and shell scripting.
- Stay up-to-date with the latest security threats.
Requirements: - 5+ years of experience in DevSecOps, DevOps, or a related field.
- Experience with AWS or deep fluency in one of GCP or Azure.
- Proficiency with CI/CD tools such as Github Actions, Jenkins, GitLab CI, or CircleCI.
- Hands-on experience with Kubernetes, including securing and managing clusters.
- Proficiency with infrastructure as code (IaC) tools such as Terraform, OpenTofu, or CloudFormation.
- Strong programming skills in Python and shell scripting.
- Knowledge of security best practices.
- Excellent problem-solving skills.
- Strong communication skills.
- Must be a US Citizen or legal permanent resident (Xometry handles ITAR data)
Xometry offers: - Opportunity to work on security in every stage of software development lifecycle