- Company Name
- Skin Analytics
- Job Title
- SecOps Engineer
- Job Description
-
**Job Title:** SecOps Engineer
**Role Summary:**
Lead the security and scalability of AWS infrastructure and CI/CD pipelines for regulated clinical software (SaMD). Design, implement, and monitor secure, automated DevOps workflows, ensuring compliance with IEC 62304, ISO 27001, HIPAA, and MDR. Collaborate cross‑functionally with engineering, QA, product, and regulatory teams to enable rapid, compliant software delivery.
**Expectations:**
- **3 months:** Deploy SAST (SonarQube) across all repos, implement DAST (OWASP ZAP) for staging, roll out secrets detection (GitLeaks/TruffleHog), and establish baseline security posture via initial penetration test with remediation backlog.
- **6 months:** Remediate all critical/high findings from initial pen test; achieve 100 % automated security gate coverage (SAST, DAST, dependency scanning) for production services.
- **12 months:** Implement full‑stack observability with ELK stack and Elastic agents, configure anomaly detection dashboards and real‑time alerts, and institute quarterly penetration testing with trend reporting.
**Key Responsibilities:**
- Own AWS security using least‑privilege and zero‑trust principles.
- Build and maintain secure CI/CD pipelines with automated gates (Snyk, SonarQube, OWASP ZAP).
- Coordinate internal and third‑party penetration testing; drive remediation.
- Deploy runtime threat detection tools (GuardDuty, Falco, Wazuh).
- Manage secret detection and scanning (GitLeaks, Vault).
- Establish observability and SIEM capabilities using ELK stack, Elastic agents, and anomaly alerting.
- Document security posture, produce reports, and communicate risks to technical and non‑technical stakeholders.
**Required Skills:**
- AWS services: EC2, S3, RDS, IAM, VPC, CloudTrail, GuardDuty, Lambda.
- CI/CD platforms (Bitbucket Pipelines or equivalent) and gated deployments.
- Security tooling: Snyk, SonarQube, OWASP ZAP, Burp Suite, Kali Linux.
- Penetration testing coordination and vulnerability management.
- Infrastructure as Code: Terraform, Ansible; containerization with Docker.
- ELK stack / SIEM implementation and management.
- Networking: VPC design, security groups, NACLs, load balancers.
- Compliance knowledge: IEC 62304, ISO 27001, HIPAA, MDR.
- Strong automation mindset, attention to detail, and clear communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience).
- Relevant certifications preferred (e.g., AWS Certified Security – Specialty, CISSP, CEH, ISO 27001 Lead Implementer).