Senior DevSecOps Engineer
Прямой работодатель СитиБанк ( citi.com )
Опыт работы любой
Citi is one of the world's top investment banks with presence in more than 160 countries and more than 200,000 employees.
We are looking for a Senior DevSecOps Engineer into a rapidly growing highly talented IT team in Markets business department. By fostering engineering excellence, applying our vast experience and continuously looking for innovations we are determined to re-energize and enhance the bank's technology platform and IT applications that run Markets all over the world.
What you will be doing
- Improve vulnerability scan solutions based on Blackduck, Checkmarx and/or Snyk
- Integration with CI/CD tooling and task management systems
- Automate security & vulnerability alerting for applications
- Development of relevant plugins for IDE / Maven / Gradle / Jenkins
- Drive evaluation and adoption of security solutions:
- HashiCorp Vault as the secrets storage solution
- SSL/TLS certificate management
- SSH PKI infrastructure with rolling (auto-expiring) SSH keys
- Improve management reporting processes based on Tableau:
- Automate reporting feeds from DevSecOps tools and internal inventory systems
- Automate ‘End of Vendor Support’ (EOVS) installed software scan process
- Development of integration APIs
- Enhance CI/CD pipelines for business applications
Our successful candidates have
- Good command of English - both written and spoken
- Unix/Linux skills at a system admin level
- Strong knowledge in computer networks and hands-on experience with their troubleshooting
- Proficiency in scripting (e.g. Bash/Perl/Python)
- Experience with build tools (Gradle/Maven preferred) and databases (Oracle/PostgreSQL preferred)
- Development experience (Java or Python or JavaScript) and are ready to code
- Understanding of distributed systems architecture, microservices, virtualization techniques
- Drive for challenge and getting their hands dirty to tackle complex issues
Would be a great plus if you know
- Basics of ITIL practices (change/incident management)
- Messaging middleware (Tibco, Solace, Kafka)
Our Technology Stack: Java/Gradle/Maven, .NET, JavaScript/Typescript, Jenkins/TeamCity, BitBucket, Artifactory, OpenShift/Kubernetes, Ansible/Chef, uDeploy, HashiCorp Vault/CyberArk, Splunk/ELK, ITRS Geneos/Grafana, OracleDB/PostgreSQL/MongoDB