Jobs and Careers
SE
Senior DevSecOps Engineer
SentinelOneCzechiafull_timeVerifiedPosted 5 Feb 2023
About the role
<p><strong>About Us:</strong></p>
<p>SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle. </p>
<p>We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!</p><h3>About the role</h3>
<p>SentinelOne is looking for a DevSecOps Engineer to create and deploy measurably effective Secure Software Development Lifecycle (SSDL) practices throughout the company. The new colleague should have a background in DevOps, Application Security assurance in a major development company and developing/deploying proactive security solutions. We need highly motivated security and technical experts to join SentinelOne’s InfoSec team to solve the problems of tomorrow while continuing to build and secure the foundation of today. Security Architects/Engineers work hands-on with technology in researching, designing, and implementing capabilities and defenses to secure and protect SentinelOne’s critical infrastructure and applications. You will also work with some of the most advanced product and platform engineers to proactively engineer security solutions.<br/><br/></p>
<h3>What will you do?</h3>
<ul>
<li>Building the security strategy governing the applications and cloud-based platform infrastructure</li>
<li>Collaborate with other infrastructure, DevOps, InfoSec and application engineers to understand the product, technology and business needs</li>
<li>Define and own guidance, alerts and security as code deployments to provide protection from malicious traffic, vulnerabilities and other attack vectors</li>
<li>Oversee building and maintaining a multi cloud infrastructure security architecture</li>
<li>Simplify automation that applies security inter-workings with CI/CD pipelines</li>
<li>Support the ability to “shift left” and incorporate security early on and throughout the development lifecycle including threat modeling and developer IDE security features.</li>
<li>Architect procedures to automate security tasks which seamlessly integrate into code builds and deployments</li>
<li>Build security utilities and tools for internal use that enable the AppSec team to operate at high speed and wide scale</li>
<li>Build and maintain monitoring, auditing, and reporting frameworks that produce artifacts that support security and compliance needs</li>
<li>Architect procedures to automate security tasks which seamlessly integrate into code builds and deployments.</li>
<li>Build security utilities and tools for internal use that enable the AppSec team to operate at high speed and wide scale</li>
<li>Integration of Security testing tools into pipeline</li>
<li>Select new application security tools including vendor/tool assessments, and conduct full POC to prove that the security solutions/products are fit-for-purpose and fit-for-use</li>
<li>Research security industry trends and best practices to share with the organization through presentations and training sessions</li>
</ul>
<h3> What skills & knowledge should you bring?</h3>
<ul>
<li> At least 5+ years’ experience in DevSecOps and Secure - SDLC</li>
<li> Experience working with development and infrastructure teams in agile workflows, including Scrum and Kanban.</li>
<li> Experience with design, implementation, and rollout of DevSecOps automation and toolchain</li>
<li> Understanding of containerized compute (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes).</li>
<li> Understanding of CloudFormation, Terraform, Ansible and Jenkins.</li>
<li> Proficient in securing Windows and *nix operating systems, applications, networking protocols and devices under a baseline requirement framework.</li>
<li> Experience with operations and security across Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP).</li>
<li> Capable of scripting in Python, Bash or PowerShell.</li>
<li> Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development lifecycle (SLDC) and how to balance the recommendations of each against business priorities.</li>
</ul>
<h4>Qualifications</h4>
<ul>
<li>Expertise in implementing and integrating CI/CD Tools from the ground up, such as Atlassian (JIRA and Confluence), Github, Jenkins, Ansible, Artifactory, Docker, Kubernetes, Selenium, SonarQube
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s