We're looking for a Senior DevSecOps Engineer to join our growing company and play a key role in our customer experience by ensuring each purchase ends in a smile!
Job Description
As aSenior DevSecOps Engineer at Sleep Country, you will be at the forefront of our DevOps and security efforts, specializing in the administration, day-to-day operations, and security of our ecosystem, with a particular focus on Oracle and Google Cloud environments. This role requires a deep understanding of Oracle technologies and applications, as well as strong leadership and problem-solving skills. You will mature our monitoring and alerting platforms while ensuring the operability, security, and compliance of our cloud-based applications and services.
Responsibilities of this role will include but are not limited to:
- Oversight, development, maintenance of all aspects of DevSecOps, such as the pipeline management, logging, monitoring, and security tooling
- Work closely with our on and offshore teams to ensure that our Oracle Retail Process Orchestration and Monitoring (POM) processes are operational
- Monitoring: Maintenance and development of our monitoring and alerting platforms
- API Administration: Oversee the administration of the Apigee API management platform, ensuring secure API development, deployment, and lifecycle management.
- Data Protection: Develop and enforce policies and procedures for data protection, compliance, and privacy in alignment with GDPR, CCPA, and other relevant regulations.
- Security: Design and implement robust security practices for cloud and hybrid systems, with a focus on minimizing risks and vulnerabilities.
- Assist with the development and implementation of security policies, controls, and best practices for our Google Cloud Platform (GCP) environment.
- Incident Response: Lead and participate incident response activities related to cloud and API security, including investigation, mitigation, and recovery processes.
- Stakeholder Engagement: Collaborate with IT, development, and business teams to integrate DevSecOps considerations into technology and business initiatives.
- Innovation and Research: Stay abreast of the latest cloud technologies, trends, and threats; recommend and implement innovative DevSecOps solutions.
- Assist application teams with on-boarding to the adopted DevSecOps tools/technologies; working with vendors to troubleshoot the platform and issues related to such integrations.
- Ensure deliverables are completed within target timeframes and are consistently of high quality, documented and support transition of operational activities.
Qualifications
- Bachelor’s degree in computer science, information systems, or a related field, or equivalent education-related experience.
- A minimum of seven years of experience in DevSecOps, with at least three years focused on cloud operations, security, and cloud management.
- At least three years of development experience in object-oriented programming languages
- Proven track record of working with teams on multi-tiered, complex distributed web applications.
- Proficiency in working with CI/CD tools.
- Familiarity with project management tools
- Experience with enterprise monitoring/alerting tools
- Practical experience with infrastructure as code tools
- Understanding of Test or Behavior Driven Development.
- Familiarity with Agile, SAFe, and DevSecOps methodologies.
- General familiarity with data protection laws and regulations (GDPR, CCPA) and experience with compliance frameworks (ISO, NIST).
- Excellent written and verbal communication skills, with the ability to convey strategic information, security, and operational topics, policies, and standards as well as risk-related concepts to both technical and non-technical audiences.
Key Technologies
- Expertise in Google Cloud Platform and Apigee, CloudRun/CloudBuild, GKE, CloudSQL, with relevant certifications such as Google Cloud Professional Security Engineer and Apigee Certified API Engineer
- Java SpringBoot or similar build and test tools.
- Jira Software Management, Confluence
- Dynatrace Performance Monitoring and PagerDuty Operations for incident response
- Hands-on experience with Git, GitLab/GitHub/CloudBuild, Kubernetes deployment, Terraform and other Agile CI/CD
#J-18808-Ljbffr