DevSecops Technical Analyst

3 weeks ago


bangalore, India Standard Chartered Bank Full time

RESPONSIBILITIES

Strategy

Towards delivering and living out our TTO Strategy 25 by Establish Strong Digital Foundations ·  Accelerate Transformation ·  Drive Process Excellence

Business

Contribute to the strategic goals of the organisation through the application of technology.  Solve problems through the application of technical knowledge and skill, determining when and how technology can solve business problems.  Scope and create technical solutions that contribute to the business’s strategic goals

Processes

Identify new areas of focus and activity for both internal and external technology communities  Develop and roll out best practice in Technology domain of expertise or their specialism.  Rescue, remediate or provide expertise on initiatives with significant technology challenge

People & Talent

Be a role model and build the appropriate culture and values.  Set appropriate tone and expectations from their team and work in collaboration with risk and control partners. Ensure the provision of ongoing training and development of people and ensure that holders of all critical functions are suitably skilled and qualified for their roles ensuring that they have effective supervision in place to mitigate any risks.  Employ, engage and retain high quality people.  Work with internal business teams, cross-functional engineering teams, and external vendors. · Effective conflict resolver and strong leadership skills to deliver on commitments and knowing when to say No to stakeholder

Risk Management

Make recommendations (and/or implement) to relevant stakeholders on possible risk management responses to identified risks and/or findings of concerns from investigations.  Manage escalations on PEP / Sensitive issues requiring additional assessment and/or control

Governance

Take personal responsibility for understanding the risk and compliance requirements of the role.  Understand and comply with, in letter and spirit, all applicable laws, and regulations, including those governing anti-money laundering, terrorist financing, and sanctions; the Group’s policies and procedures; and the Group Code of Conduct.  Effectively and collaboratively identify, escalate, mitigate and resolve risk and compliance matters.  Embed the Group’s values and code of conduct to ensure that adherence with the highest standards of ethics, and compliance with relevant policies, processes, and regulations among employee’s form part of the culture

Regulatory & Business Conduct

Display exemplary conduct and live by the Group’s Values and Code of Conduct.  Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct. Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters. Lead to achieve the outcomes set out in the Bank’s Conduct Principles

Other Responsibilities

Embed Here for good and Group’s brand and values, Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures; Multiple functions (double hats)

OUR IDEAL CANDIDATE

EDUCATION

Bachelor's degree in Computer Science, Software Engineering, or a related field Overall 8+ Years of experience in information technology out of which 4+ years of experience in Cyberand cloud technologies

TRAINING

Experience in technical writeups, requirement gathering, documentation in cyber & cloud technologies Experience and practice about writing professional documents. Responsible for technical writeups, presentation, hackathon and roadshows Responsible for writing and maintaining the documentation relating cyber and cloud technologies  Familiarity with one or more threat modeling methodologies (, MITRE, STRIDE, PASTA, LINDDUN, CVSS, Attack Trees, Security Cards, hTMM, Quantitative Threat Modeling Method, VAST Modeling, OCTAVE) Familiarity in Mitre Attack Navigator, Mitre Defend Integrate / Leverage ChatGPT to perform threat modeling Familiarity in Threat Modeling Automation tools and creating / consuming threat libraries Familiarity in tools such as AttackIQ, Cymulate, Pentera, SafeBreach, Verodin (Mandiant Security Validation) Exposure on programming languages Exposure on DevOps tools, for ex. Bitbucket, Jenkins and Artifactory Experience with Public Cloud platforms, for ex. AWS, Azure or GCP Experience in cybersecurity processes with reference to NIST CSF Critical thinking and problem-solving skills  Certified on Microsoft Azure Security Technologies, AWS security speciality and ATT&CK for Cyber Threat Intelligence are preferred Partner with stakeholders to learn and understand a wide variety of threat model subjects An adversarial mindset - candidate must be able to put themself in the mind of the attacker Familiarity in penetration testing and red team methodologies  Exposure using common penetration testing tools using Burpsuite, Metasploit etc., 

CERTIFICATIONS

Cloud or Container Certifications like AWS SA, AZ-500, TF Associate Certified on Microsoft Azure Security Technologies, AWS security speciality and ATT&CK for Cyber Threat Intelligence are preferred Certification on Operationalizing MITRE ATT&CK, Foundations of Breach & Attack Simulation, Application of ATT&CK Navigator, Extending ATT&CK with ATT&CK Workbench

LANGUAGES

Exposure on programming languages Exposure on Infrastructure as Code (IAC) tools like Terraform, Cloud formation  Familiarity DevOps tools, for ex. Bitbucket, Jenkins and Artifactory Experience with Public Cloud platforms, for ex. AWS, Azure or GCP Familiarity in API layer like security, custom analytics, throttling, caching, logging, monetization, request and response modifications etc.  Familiarity with Container platforms, for ex. Kubernetes, OpenShift, EKS, AKS or GKE Familiarity in automation using Cloud services, like AWS Lambda or Step Function Exposure creating Splunk use cases (SIEM) and Splunk query language

Role Specific Technical Competencies

Threat Modeling (Manual / Automation) Threat Modeling Framework STRIDE, MITRE Azure / AWS Public Cloud Python, Go Lang, Java / .NET Infrastructure as Code PowerShell, Azure CLI, Technical Writeups, Documentation
  • DevSecOps Analyst

    2 months ago


    Bangalore, India Experis IT Private Limited Full time

    DevsecOps Analyst - Bachelor's degree in Computer Science, Information Technology, or a related field.- 2-3 of experience in DevSecOps.- Strong understanding of DevSecOps principles and practices.- Knowledge of security tools and technologies, such as vulnerability scanners, intrusion detection systems, and ELK stack.- Experience with cloud platforms...

  • DevSecOps Analyst

    3 weeks ago


    Bangalore, India Experis IT Private Limited Full time

    DevsecOps Analyst - Bachelor's degree in Computer Science, Information Technology, or a related field.- 2-3 of experience in DevSecOps.- Strong understanding of DevSecOps principles and practices.- Knowledge of security tools and technologies, such as vulnerability scanners, intrusion detection systems, and ELK stack.- Experience with cloud platforms...

  • Lead Analyst

    4 weeks ago


    bangalore, India CGI Full time

    Position Description: Company Profile:At CGI, we’re a team of builders. We call our employees members because all who join CGI are building their own company - one that has grown to 72, professionals located in 40 countries. Founded in , CGI is a leading IT and business process services firm committed to helping clients succeed. We have the...

  • DevSecOps Manager

    1 month ago


    bangalore, India Philips Full time

    JOB DESCRIPTION Job Title DevSecOps Manager Job Description DevSecOps Manager - Finance We have a dynamic and exciting career opportunity and are looking for an extraordinary candidate for this role! The DevSecOps Manager is responsible for managing the E2E design, build, testing, deploying and running the platform. The main objective...

  • DevSecOps Manager

    1 month ago


    Bangalore, India Philips Full time

    Job TitleDevSecOps ManagerJob DescriptionDevSecOps Manager - FinanceWe have a dynamic and exciting career opportunity and are looking for an extraordinary candidate for this role!The DevSecOps Manager is responsible for managing the E2E design, build, testing, deploying and running the platform. The main objective for the DevSecOps manager is to deliver...

  • DevSecOps Manager

    3 weeks ago


    Bangalore, India Philips Full time

    Job TitleDevSecOps ManagerJob DescriptionDevSecOps Manager - FinanceWe have a dynamic and exciting career opportunity and are looking for an extraordinary candidate for this role!The DevSecOps Manager is responsible for managing the E2E design, build, testing, deploying and running the platform. The main objective for the DevSecOps manager is to deliver...

  • DevSecOps Engineer

    4 weeks ago


    bangalore, India Unisys Full time

    What success looks like in this role: Responsibilities 1Analyzing, Building Processes, Executing, and streamlining DevsecOps practices 2Automating processes with the right tools 3Develop best in class Runbooks for Devsecops for our Field Delivery as well as Facilitatinginternal development process and operations 4Establishing a suitable...


  • bangalore, India Western Digital Full time

    Company Description Western Digital's reliance on software development workflows is growing by leaps and bounds as a leading provider of Storage Solutions. As Secure Development Factory (SDF) Senior Infrastructure Engineer, you will be at the heart of Western Digital’s engineering process, delivering the software development tools and...


  • bangalore, India Western Digital Full time

    Company Description Western Digital's reliance on software development workflows is growing by leaps and bounds as a leading provider of Storage Solutions. As Secure Development Factory (SDF) Senior Infrastructure Engineer, you will be at the heart of Western Digital’s engineering process, delivering the software development tools and...


  • bangalore, India Unisys Full time

    What success looks like in this role: Analyzing, Building Processes, Executing, and streamlining DevsecOps practices Automating processes with the right tools Develop best in class Runbooks for Devsecops for our Field Delivery as well as Facilitatinginternal development process and operations Establishing a suitable DevSecOps channel across the...


  • bangalore, India Unisys Full time

    What success looks like in this role: Analyzing, Building Processes, Executing, and streamlining DevsecOps practices Automating processes with the right tools Develop best in class Runbooks for Devsecops for our Field Delivery as well as Facilitatinginternal development process and operations Establishing a suitable DevSecOps channel across the...


  • bangalore, India The Cigna Group Full time

    Salesforce DevSecOps Engineer We are looking for passionate Trailblazers to join our Technology team supporting Cigna healthcare International Markets’ Salesforce organisations. Salesforce DevSecOps Engineers are the core of our Salesforce Platform team, responsible for making sure we get the most value from our Salesforce DevSecOps tools, improving...


  • bangalore, India The Cigna Group Full time

    Salesforce DevSecOps Engineer We are looking for passionate Trailblazers to join our Technology team supporting Cigna healthcare International Markets’ Salesforce organisations. Salesforce DevSecOps Engineers are the core of our Salesforce Platform team, responsible for making sure we get the most value from our Salesforce DevSecOps tools, improving...


  • bangalore, India MUFG Full time

    About the Role:Position Title: Security Engineer - DevSecOpsLocation: BengaluruJob ProfilePosition details:As a DevSecOps Security Engineer at MUFG, you will be responsible for providing in depth subject matter expertise in automating, monitoring, and applying security at all phases of the Software Development Life Cycle, and the delivery of trusted products...

  • DevSecOps

    3 weeks ago


    bangalore, India Michael Page Full time

    Opportunity to be at the forefront of a fast-growing product company Be a part of an open, flat and meritocratic organization About Our Client Our client is a pioneering healthtech company based in Bangalore, dedicated to transforming the healthcare industry through innovative software solutions. As a Series-A funded SaaS company, our focus is...

  • DevSecOps

    4 weeks ago


    bangalore, India Michael Page Full time

    Opportunity to be at the forefront of a fast-growing product company Be a part of an open, flat and meritocratic organization About Our Client Our client is a pioneering healthtech company based in Bangalore, dedicated to transforming the healthcare industry through innovative software solutions. As a Series-A funded SaaS company, our focus is...


  • bangalore, India MUFG Full time

    About the Role: Position Title: Security Engineer - DevSecOps Location: Bengaluru Job Profile Position details: As a DevSecOps Security Engineer at MUFG, you will be responsible for providing in depth subject matter expertise in automating, monitoring, and applying security at all phases of the Software Development Life Cycle, and the delivery of...


  • bangalore, India MUFG Full time

    About the Role:Position Title: Security Engineer - DevSecOpsLocation: BengaluruJob ProfilePosition details:As a DevSecOps Security Engineer at MUFG, you will be responsible for providing in depth subject matter expertise in automating, monitoring, and applying security at all phases of the Software Development Life Cycle, and the delivery of trusted products...

  • DevSecOps

    3 weeks ago


    bangalore, India 5100 Kyndryl Solutions Private Limited Full time

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The...


  • bangalore, India Corporate Resources Full time

    Job Description We are looking for an experienced and versatile technical business analyst to improve our information technology systems In this role, your duties will include developing software programs to improve our business operations You may also be required to provide training To ensure...