DevSecOps Engineer
OddballFull Time
Mid-level (3 to 4 years), Senior (5 to 8 years)
Candidates should possess 5+ years of experience in information security or compliance engineering roles, along with practical experience with DevOps security practices, including integrating security controls into CI/CD pipelines, a strong understanding and hands-on experience with ISO 27001, SOC 2 (Type I and II), and NIST SP 800-53, and familiarity with cloud-native security (AWS, GCP, or Azure) and container orchestration tools like Terraform, Helm, or Ansible.
The Staff Engineer – DevSecOps will follow established processes for the implementation and maintenance of security controls aligned with ISO 27001, SOC 2, and NIST 800-53, collaborate with security leadership to ensure adherence to these controls and procedures, collaborate with internal and external auditors to support audits and remediation efforts, develop and maintain automated security and compliance monitoring tools and dashboards, translate regulatory requirements into technical requirements and integrate them into the SDLC, execute tasks related to the implementation and upkeep of compliance controls under ISO 27001, SOC 2, and NIST 800-53 guidance, conduct gap assessments and risk analysis, define and track remediation efforts to ensure compliance readiness, and possess strong hands-on experience and understanding of Kubernetes security, including RBAC, pod security policies, network policies, and secrets management.
Provides advanced networking solutions and services
Extreme Networks specializes in advanced networking solutions that optimize and secure network operations for a variety of clients, including educational institutions, retail businesses, government agencies, and healthcare facilities. Their products include network infrastructure such as switching and routing solutions, wireless connectivity, and data center fabrics, along with cloud-based services and advanced security measures. Extreme Networks differentiates itself by offering both hardware and software solutions, as well as professional and managed services that ensure efficient network operations. Their goal is to provide comprehensive support and training to help clients maximize their networking capabilities.