Conduct comprehensive security assessments, including threat modelling, vulnerability scanning
Implement security controls and best practices in the software development lifecycle (SDLC).
Develop and enforce secure coding standards and guidelines.
Integrate security tools such as Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) into CI/CD pipelines.
Perform regular code reviews and security audits to identify and mitigate vulnerabilities, including injection attacks in API parameters.
Responsibilities
Cloud and Infrastructure Security:
Design and implement secure cloud architectures on AWS, particularly using Amazon EKS for container orchestration.
Ensure compliance with industry standards and regulations (e.g., GDPR, HIPAA, PCI-DSS).
Implement Identity and Access Management (IAM) policies and practices.
Utilize containerization technologies (Docker, Kubernetes) for secure application deployment.
Ensure secure communication between services running in AWS EKS clusters.
Experience with AWS services such as Lambda for serverless computing, CloudWatch for monitoring and logging, and various AWS databases for secure data storage and management
Experience with infrastructure as code using Terraform and build automation with Gradle.