
Vodafone • Kinshasa, Congo, the Democratic Republic of the
CYBER SECURITY DEVSECOPS SPECIALIST
8.4
/10
Transparency ranking
Job Description
ROLE PURPOSE
The DevSecOps Specialist will be crucial in integrating security practices within the DevOps process, ensuring our organisation's software and infrastructure are safeguarded from evolving cyber threats.
Key accountabilities
- The primary responsibility of the DevSecOps Specialist will be to identify security risks through threat modelling, develop robust mitigation strategies, and implement advanced security measures throughout the software development lifecycle.
- Key duties include application threat modelling, assessing code and applications to ensure they are vulnerability-free before being shipped to production environments in alignment with the organisation's Secure-by-Design framework.
- Responsibilities will also encompass maintaining the security of application or APIs throughout the product lifecycle, consistent with the DevSecOps continuum and internal security standards.
- Additional tasks involve monitoring and securing the CI/CD pipeline, conducting comprehensive security audits, responding to and investigating security incidents, and establishing/enforcing stringent security protocols.
- Furthermore, the DevSecOps Specialist will provide security expertise to development and operations teams, fostering a culture of security awareness and adherence to best practices.
Staying current on the latest cyber threats and security technologies is essential for effectively protecting the organisation's assets. - Proficiency in fundamental programming languages such as JavaScript (React JS, Next JS, Angular JS), Node JS, Golang, Python and Java is a prerequisite. Additionally, C++, C#, scripting skills in Bash and PowerShell are considered a plus.
- Experience with cloud platforms like AWS, Azure, Google Cloud Platform (GCP), and IBM Cloud is essential, along with an understanding of cloud security best practices relevant to these environments.
- Knowledge of containerization and orchestration solutions, including Docker, Kubernetes, and OpenShift, is important. An appreciation of the security aspects of containerization, such as image scanning and runtime security, is highly valued.
- Candidates should have exposure to CI/CD pipeline tools like Jenkins, GitHub Actions GitLab CI/CD, CircleCI, and Travis CI and experience integrating security into CI/CD pipelines.
Knowledge of Infrastructure as Code (IaC) using tools like Terraform, CloudFormation, Ansible, Chef, and Puppet is necessary, with a desirable understanding of security practices in IaC environments. - Extensive exposure to security tools and technologies is required. This includes Static Application Security Testing (SAST) tools like SonarQube and Checkmarx, Dynamic Application Security Testing (DAST) tools like OWASP ZAP and Burp Suite, Software Composition Analysis (SCA) tools like WhiteSource (Mend.io) and Snyk, and Runtime Application Self-Protection (RASP) tools.
- A solid appreciation of network security, including firewalls, VPNs, Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS), is essential. An understanding of network protocols and security, such as TCP/IP, HTTP/HTTPS, Network zoning model and SSL/TLS, is also important.
- An understanding of threat modelling and vulnerability management is required, as well as experience using tools like the Microsoft Threat Modeling Tool, OWASP Threat Dragon, and vulnerability scanners like Nessus and Qualys.
- The ability to implement application monitoring and logging tools like Splunk, the ELK Stack (Elasticsearch, Logstash, Kibana), Prometheus, and Grafana is necessary.
CORE RESPONSIBILITIES MANAGEMENTS
- Knowledge of integrating with Security Information and Event Management (SIEM) tools is also desirable.
- Some exposure to Identity and Access Management (IAM) tools like Okta, Auth0, AWS IAM, and Azure AD is preferred. Knowledge of Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) is critical.
- An understanding of databases, including relational databases like Oracle, MySQL, PostgreSQL, and SQL Server, is preferred and NoSQL database as well such as MongoDB and Kassandra DB. This includes the ability to construct efficient queries, optimize database performance, and ensure data integrity and security.
- Additionally, a good understanding of secure development and assessment of application programmable interfaces (APIs) is a critical skill.
- This involves knowledge of RESTful and SOAP APIs, implementing secure API authentication and authorization mechanisms, and conducting regular security assessments to identify and mitigate potential vulnerabilities
QUALIFICATION AND EXPERIENCE
- Minimum of 3-5 years of experience in Cyber Security
- Bachelor's degree in computer science, information technology, cyber security, or a related field.
- Security-related certifications such as DevOps Institute's DevSecOps Foundation; Certified Kubernetes Security Specialist (CKS); AWS, Azure, or GCP Certified DevOps Engineer
- Candidates should have a strong knowledge of cyber security principles and best practices.
- Exposure to DevSecOps Standards and Frameworks such as NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CIS Controls, and OWASP Top Ten.
- Candidates must be well-versed in DevOps and DevSecOps frameworks, such as the DevOps Institute's DevSecOps Foundation, and thoroughly understand Continuous Integration and Continuous Delivery (CI/CD) best practices.
- Candidates are expected to have strong collaboration and communication skills, with the ability to work effectively across development, operations, and security teams.
- They must also be capable of articulating security findings and recommendations clearly.
- Problem-solving and critical thinking are essential, including analytical skills to identify security vulnerabilities and threats and strategic thinking to implement effective security solutions.
- Project management skills are a plus, including the ability to manage multiple projects, prioritize tasks, and a familiarity with Agile methodologies and tools like Jira.
- Continuous learning is required, emphasizing staying up to date with the latest security trends, threats, and technologies.
- This includes participation in relevant training, certifications, and conferences.
- Excellent communication skills [French and English]
Company benefits
UK (28), India (22), Egypt (21), Hungary (20), Romania (20), Albania (22), Turkey (14) days annual leave + bank holidays
Work from anywhere scheme – work for up to 20 days/year abroad (dependant on country)
Annual bonus – dependant on company performance
Employee discounts
Personal development days – once per quarter
Learning platform – access to Harvard Business Publishing, MIT Horizon and Skillsoft
Enhanced maternity leave – 16 weeks (paid) with a phased return to work over 6 months
Enhanced paternity leave – 16 weeks (paid) with a phased return to work over 6 months
Volunteer days – up to 5 days
Coaching – access to a free certified internal pool of coaches
Mentoring
Carer’s leave
Adoption leave – 16 weeks (paid) with a phased return to work over 6 months
Enhanced sick days
Mental health platform access
Mental health first aiders
Employee assistance programme
Complimentary Medical Services – 24/7 online doctor service
Compassionate leave
Home office set up
Buddy scheme
Referral bonus
Early finish Fridays
Buy or sell annual leave
Cycle to work scheme
Life insurance
Sabbaticals
Salary sacrifice
Share options
Teambuilding days
Faith rooms
Enhanced pension match/contribution
LinkedIn learning license
Working at Vodafone
Company employees:
85,887
Gender diversity (m:f):
61:39
Hiring in countries
Albania
Belgium
Cyprus
Czechia
Democratic Republic of the Congo
Egypt
France
Germany
Greece
Hungary
India
Ireland
Italy
Lesotho
Luxembourg
Mozambique
Portugal
Romania
South Africa
Spain
Tanzania
Türkiye
United Kingdom
United States
Office Locations
Other jobs you might like
Cyber Security Operations Specialist
Kinshasa, Congo, the Democratic Republic of the
30 Jan
Transparency8.4/10
RankingCode/Dev Security Engineer
India
9 Jan
Transparency10/10
RankingATR - Development Security Operations Expert
Toulouse, France
Transparency9.2/10
RankingDevOPS Engineer - Cyber-Training Platform (m/f)
Madrid, Spain
29 Jan
Transparency9.2/10
RankingCyber Security Engineer - SOC (H/F)
Paris, France
9 Jan
Transparency9.2/10
Ranking