- Company Name
- ConvexTech Inc.
- Job Title
- Security Engineer
- Job Description
-
Job Title: Security Engineer
Role Summary:
Design, implement, and maintain automated security controls for containerized environments, hardening internal platforms while reducing developer friction. Lead improvements to the container SDLC, focusing on image scanning, risk mitigation, and DevSecOps practices across cross‑functional teams.
Expectations:
• 6‑12+ month contract period.
• Prior experience in finance or investment banking preferred.
• Successful candidates will demonstrate strong communication skills and the ability to collaborate with DevOps, platform, and development communities.
Key Responsibilities:
1. Architect and deploy secure container solutions using Kubernetes, Docker, Podman, and OpenShift.
2. Design and automate container image scanning pipelines; integrate scanners into CI/CD workflows.
3. Define and enforce security baselines, governance, and threat models for containerized applications.
4. Collaborate with platform and DevOps teams to embed security into development lifecycles and reduce friction.
5. Conduct architecture reviews, assess scalability, reliability, and security of existing systems.
6. Mentor developers on secure coding practices and container hardening techniques.
7. Produce documentation, runbooks, and best‑practice guides for security operations.
Required Skills:
• 7+ years of enterprise software security engineering experience.
• Deep knowledge of Kubernetes, Docker, Podman, OpenShift and related container runtimes.
• Strong foundation in DevSecOps, security fundamentals, and risk mitigation for container platforms.
• Expertise in a major programming language (Python or Java) and related tooling (Git, Maven/Gradle, IDEs, Jenkins, Bitbucket).
• Proficiency with CI/CD, Agile methodologies, and vulnerability scanning tools.
• Excellent problem‑solving, interpersonal, and written communication abilities.
Required Education & Certifications:
• Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
• Relevant certifications such as Certified Kubernetes Security Specialist (CKS), Certified Information Systems Security Professional (CISSP), or Red Hat Certified Engineer (RHCE) are advantageous.