Job Description:
DevSecOps Manager (Development+ Security+ Operations)
Support the development and maintenance of DevSecOps procedures, standards, and policies to establish a strong
baseline of secure development best practices across the organization
Drive and support recurring secure development training programs and awareness initiatives for development and engineering teams
Enforce information security policies, procedures, and practices aligned with published industry standards
Ensure compliance with governance standards through internal audits and independent third-party verification
Support teams in defining and implementing secure development initiatives and DevSecOps roadmaps
Maintain and update scorecards to track compliance against DevSecOps-related KPIs and security metrics
Collaborate with development and engineering teams to continuously improve DevSecOps processes, tools, and automation
Integrate security tools into CI/CD pipelines using APIs, plugins, and automation frameworks
Work closely with engineering teams to ensure security is embedded while architecting and building new systems
Review and analyze risks associated with open-source components and third-party dependencies using Software Composition Analysis (SCA) tools
Detect insecure modules, libraries, and dependencies within applications and recommend remediation actions
Prepare security vulnerability, risk, and compliance reports for management review
Manage DevSecOps-related issues and drive management decisions toward timely resolution
Support secure coding methodologies and operational security solutions for complex business and technology environments