Semtech Logo

Semtech

Sr. Staff Engineer DevSecOps

Posted 3 Days Ago
Be an Early Applicant
India
Senior level
India
Senior level
The Sr. Staff Engineer DevSecOps is responsible for implementing and maintaining the DevSecOps strategy, establishing security governance, managing security tools, and ensuring automation of security processes. This role involves collaborating across teams, assessing security risks, maintaining security policies, and fostering a culture of continuous learning in the organization.
The summary above was generated by AI

Responsibilities:

DevSecOps Strategy:

  • Implement the Semtech DevSecOps strategy to integrate security seamlessly into the software development lifecycle.

  • Collaborate with cross-functional teams to establish and maintain secure coding standards, continuous integration, and continuous delivery pipelines.

DevSecOps Planning:

  • Establish clear project security goals and objectives, defining and prioritizing security requirements to align with organizational objectives.

  • Identify and assess potential security risks and threats, developing a comprehensive threat model for the application.

  • Set up a robust security governance structure within the project, implementing a security architecture plan and documenting all aspects of the planning process for future reference.

Security Automation:

  • Evaluate, implement, and manage security tools and technologies within the DevOps toolchain to automate security testing, vulnerability scanning, and compliance checks.

  • Ensure the tools are effectively utilized to identify and remediate security vulnerabilities early in the development process.

  • Drive the automation of security controls and processes to enhance efficiency and reduce manual intervention.

  • Implement automated security testing, code analysis, and deployment validation to maintain a high level of security without impeding development velocity.

  • Develop and maintain automated security processes for infrastructure as code (IaC) deployments.

Operations & Monitor:

  • Maintain an incident response plan specific to DevOps processes, ensuring rapid identification, containment, eradication, and recovery from security incidents.

  • Collaborate with incident response teams to integrate DevOps-related incidents into the overall organizational response plan.

  • Implement security monitoring and adhere to incident response procedures to detect and respond swiftly to security incidents.

  • Set up automated log and event monitoring, continuously updating and patching all components across production, pre-production, and development environments to minimize vulnerabilities.

  • Monitor all environments (Prod, Pre-Prod, Dev) for security events.

  • Review and update access controls, permissions, and security policies regularly, documenting all monitoring practices for reference and improvement.

  • Working closely with DevOps to update and patch all components in all environments to address known vulnerabilities and enhance overall security

Continuous Learning:

  • Stay current with industry trends, emerging threats, and security technologies.

  • Implement a culture of continuous learning within the team, encouraging certifications, training, and knowledge sharing.

Minimum Qualifications:

  • Bachelor's degree in computer science, information technology, or a related field (master's degree preferred).

  • Extensive experience in cloud architecture and strategy with a proven track record of successful cloud adoption.

  • Proven experience as a DevSecOps Engineer in AWS cloud environments.

  • Strong understanding of cloud security principles and best practices.

  • Hands-on experience with security tools such as AWS Security Hub, WAF, and third-party security solutions.

  • Proficiency in scripting and automation languages (e.g., Python, Shell, PowerShell).

  • Experience with CI/CD tools and practices such as GitHub actions, Chef, Anisble, Salt, Puppet,etc.

  • Knowledge of containerization and orchestration technologies (e.g., Docker, Kubernetes).

  • Certifications: AWS Certified Security – Specialty, Certified DevOps Engineer, or Certified Information Systems Security Professional (CISSP).

  • Strong analytical and problem-solving skills.

Top Skills

Powershell
Python
Shell

Similar Jobs

3 Days Ago
Bangalore, Bengaluru, Karnataka, IND
Hybrid
21,000 Employees
Senior level
21,000 Employees
Senior level
Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
The Senior Software Engineer will lead DevOps initiatives by ensuring smooth CI/CD operations, developing automation tools, and modernizing build infrastructure. Responsibilities include collaborating with teams to resolve CI/CD issues, improving security and reliability, and implementing best practices in software development.
Be an Early Applicant
20 Hours Ago
Bangalore, Bengaluru, Karnataka, IND
900 Employees
Mid level
900 Employees
Mid level
Information Technology
As a Software Engineer on the Platform Engineering team at StockX, you will enhance and maintain the foundational components that support engineering efforts, focusing on building resilient services, collaborating with teams to apply new technologies, mentoring others, and automating cloud-related tasks.
Be an Early Applicant
3 Hours Ago
Hyderabad, Telangana, IND
11,000 Employees
Expert/Leader
11,000 Employees
Expert/Leader
eCommerce • Fashion
As a Staff Software Engineer for Power BI at Gap Inc., you will define customer technical requirements, create design specifications, build dashboards and semantic models, collaborate with stakeholders, and improve coding practices. Your role includes conducting code reviews, recommending technologies, and participating in a DevOps team using automated release practices.

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account