Walker & Dunlop's WDTech Information Security department is seeking a Senior Cloud and Software Development Security Engineer to enhance the security posture of their cloud and application environments, including AWS, Azure, Kubernetes, and CI/CD pipelines, by designing and implementing robust security architectures and embedding 'security as code' practices.
Requirements
- Significant technical experience in AWS and Azure cloud computing technologies and automation (HashiCorp, Terraform, GitLab, JIRA, etc.).
- Experience in DevOps environments working with and influencing developers to maintain security through CI/CD processes.
- Proficient and up to date with Azure and AWS.
- Hands on experience with Azure Resource Manager, AWS CloudTrail, AWS IAM, AWS Security Hub, AWS Control Tower.
- Experience with the development, deployment, and automation of security solutions in an enterprise cloud-based environment.
- Knowledge of network based, system level, and application layer attacks and mitigation methods.
- Knowledge of technical security control environments and compliance frameworks including NIST Cloud Security Frameworks, CSA CCM, ISO 27017.
Responsibilities
- Assess, design, and document security solutions and processes for Amazon Web Service (AWS) and Azure.
- Work with software developers on secure best practices in Infrastructure as Code, cloud design patterns and CI/CD with built-in application security controls.
- Work with key areas of business and IT to develop baseline network, cloud, container, and application security standards and integrate into the CI/CD pipeline.
- Implement and automate “security as code” using cloud services and CI/CD components as necessary.
- Design security architecture, methods, and controls required to meet security, compliance, and audit requirements.
- Perform regular security audits and automated compliance checks on AWS and Azure resources.
- Collaborate with SRE and development teams to ensure secure coding, build, and deployment practices.
Other
- Lead and manage security projects.
- Direct tasks and develop milestones for Information Security projects in support of Information Security goals in line with the Company's direction.
- Develop metrics and provide regular reports to senior management.
- Set requirements and direct managed security service providers (MSSPs) to ensure that they are appropriately managing the services to provide security to the company.
- Provide 24/7 on-call support for security incidents related to network systems and infrastructure.