Job Openings DevSecOps Architect - eCommerce Security (Remote, US)

About the job DevSecOps Architect - eCommerce Security (Remote, US)

This role is remote, US.

Expectations

  • Must be a US Citizen or Green Card holder or Visa Transfer (H1 or TN)
  • 10+ years as a Technical Security Engineer
  • 5+ years DevSecOps experience (5-7+ years preferred)
  • Extensive DevSecOps experience in the retail domain and e-commerce design space
  • Expert who can communicate needs and influence throughout the organization
  • Excellent communication skills
  • Knowledge of AWS, REACT, NODE.JS and Redux
  • Creative eye for design

Additional Position Expectations

  • Must have enterprise or retail level applications
  • Strong understanding of retail domain and eCommerce design and operational processes
  • Experience in DevSecOps working with developers and engineering teams in a dynamic environment to promote / implement DevSecOps throughout the organization
  • Development and maintenance / management of architecture-based documentation
  • Knowledge of open source and commercial application security tools and frameworks
  • Experience with modern security and defense mechanism applications
  • Experience in exploiting web apps and providing guidance on web services security vulnerabilities: cross-site scripting, cross-site request forgery, SQL injection, DoS attacks, XML / SOAP, and API attacks
  • Expert knowledge of DDos techniques, OWASP risks, Vulnerabilities, and Mitigation Mechanisms
  • Proficiency in common network and web protocols
  • Prior work in cloud environments and understanding of cloud infrastructure
  • CI / CD software pipelines experience
  • Work experience with on-site and off-site development teams, coordinating work, expectations, and delivery

Job Description

You will be responsible for the overall design and direction of eCommerce Security Engineering across all of our applications. This role is critical in the development and ongoing security posture for digital commerce applications.

Accountable for identifying and implementing our security principles and best practices to maintain application security and address the impact of non-human HTTP traffic on both the performance and security of the application by applying blocks, rate limits, tarpits, or other remediation.

  • You will be partnering with the Security Team on Vulnerability Scanning, will manage SSL certificates, assist with cloud architecture IAM needs, create processes for analyzing web traffic to identify patterns of abuse on the website, provide guidance and/or implement mitigation to address discovered abuse patterns using modern security tools, and work with developers and performance engineers to assist in securing the solution
  • As a subject matter expert, this role will leverage various monitoring tools to analyze the security posture of both systems and applications while working independently and collaboratively to address any issues discovered
  • Through collaboration with software development and platform engineers, threat models will be reviewed and corresponding mitigation policies will be applied
  • You will be accountable to protect all external endpoints to the application stack and facilitate vulnerability scans / remediations

Perks

    • Unlimited personal leave
    • Health and Life Insurance
    • Medical, Dental, and Vision insurance
    • 401K matching
    • Fun and flexible environment
    • Parental leave
    • Public company

    Industry: Fashion, eCommerce