The DevSecOps, Cloud & OT Security Specialist will be responsible for embedding security into the DevOps lifecycle, securing cloud-native and OT environments, and implementing security automation across CI/CD pipelines. The role involves designing, implementing, and managing security controls for IT and OT systems, ensuring compliance, and protecting critical infrastructure and applications from modern cyber threats.
Key Responsibilities:
1. DevSecOps Integration:
- Integrate security tools and practices within CI/CD pipelines (e.g., GitLab, Jenkins, Azure DevOps, GitHub Actions).
- Automate SAST, DAST, SCA, and container security scanning.
- Develop and maintain IaC security checks (Terraform, CloudFormation, Ansible).
- Implement secret management and secure credential handling in DevOps workflows.
2. Cloud Security Architecture & Operations:
- Design and enforce security controls for multi-cloud environments (AWS, Azure).
- Implement and manage cloud-native security services (AWS Security Hub, Azure Defender).
- Conduct threat modeling, risk assessments, and security posture reviews for cloud infrastructure.
- Ensure compliance with ISO 27001, NIST, CIS Benchmarks, DPDP, and LGPD.
3. OT Security:
- Secure Industrial Control Systems (ICS), SCADA, and IoT devices in OT environments.
- Implement network segmentation, secure remote access, and anomaly detection for OT networks.
- Conduct OT-specific risk assessments and vulnerability management aligned with IEC 62443.
- Collaborate with plant operations teams to ensure minimal disruption during security implementations.
4. Vulnerability Management & Incident Response:
- Perform vulnerability assessments across IT, OT, and cloud environments.
- Respond to and investigate security incidents in DevOps, cloud, and OT systems.
- Continuously monitor and improve security posture using SIEM and SOAR solutions.
5. Governance, Risk & Compliance:
- Establish security baselines and best practices across IT, OT, and DevOps processes.
- Ensure compliance with data protection laws, privacy frameworks, and audit requirements.
- Collaborate with GRC and IT teams for audit readiness and documentation.
6. Collaboration & Enablement:
- Partner with developers, SREs, OT engineers, and IT operations to promote secure coding and deployment practices.
- Conduct training sessions and workshops on DevSecOps, cloud security, and OT security principles.
- Act as a security advisor in solution design, architecture reviews, and technology selection.
Required Skills & Experience:
- Strong hands-on experience with CI/CD tools and integrating security automation.
- Proficiency in cloud security architecture and hardening (AWS/Azure).
- Experience with OT security frameworks (IEC 62443) and ICS/SCADA environments.
- Knowledge of containerization and orchestration security (Docker, Kubernetes).
- Familiarity with IaC security, API security, and serverless application security.
- Good scripting skills for automation and tool integration.
- Experience with SIEM, SOAR, and cloud-native security tools.
Preferred Skills:
- Experience with Zero Trust Architecture and cloud identity management (IAM, PAM).
- Familiarity with DevSecOps maturity models and security-as-code principles.
- Exposure to penetration testing or red-teaming within CI/CD, cloud, or OT environments.
Soft Skills:
- Excellent communication and stakeholder management skills.
- Analytical thinker with a problem-solving mindset.
- Ability to work in fast-paced, cross-functional, and agile environments.