Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
[Job-19070] Architect (Security & DevSecOps Support), Colombia image - Rise Careers
Job details

[Job-19070] Architect (Security & DevSecOps Support), Colombia

We are tech transformation specialists, we are CI&T.


We combine the disruptive power of Artificial Intelligence with human expertise to support large companies in navigating changes in technology and business. With 30 years of experience, 6,000 workers, offices in 10 countries and talents across 5 continents. We operate in the fields of design, strategy, and engineering for global brands, helping clients achieve the full potential of technology as a force for good. Impact is what we deliver.


Mission:


As an Architect in Security & DevSecOps Support, you will play a pivotal role in enhancing the security posture of our development pipelines and frameworks. Your mission is to assist in the design and implementation of secure Continuous Integration and Continuous Deployment (CI/CD) processes, ensuring that security is embedded at every stage of the software development lifecycle. You will collaborate closely with engineering teams to foster a culture of security awareness and efficient DevSecOps practices.


Responsibilities:


- Assist in designing secure CI/CD pipelines that integrate security best practices.

- Collaborate with cross-functional teams to implement and optimize DevSecOps practices.

- Support the development of security frameworks and guidelines.

- Participate in security assessments and audits of CI/CD processes and tools.

- Help to identify vulnerabilities and recommend mitigation strategies.

- Assist in the automation of security testing and compliance checks within the CI/CD pipeline.

- Stay current with industry trends and emerging technologies in security and DevSecOps.


Requirements:


- Understanding of software development processes and methodologies.

- Familiarity with CI/CD tools (e.g., Jenkins, GitLab CI, CircleCI, etc.).

- Knowledge of security principles and practices, including application security and cloud security.

- Understanding of scripting and automation (e.g., Python, Bash, PowerShell).

- Familiarity with containerization and orchestration technologies (e.g., Docker, Kubernetes).

- Advanced English level


Nice to Haves:


- Experience with security tools (e.g., static/dynamic analysis tools, vulnerability scanners).

- Familiarity with cloud platforms (e.g., AWS, Azure, Google Cloud) and their security features.

- Knowledge of compliance frameworks (e.g., GDPR, HIPAA, PCI-DSS).

- Understanding of networking concepts and security measures.

- A passion for continuous learning and staying informed about the latest in cybersecurity and DevSecOps.


#LI-SC1

#MidSenior


Our benefits include:


- Premium Healthcare

- Meal voucher

- Maternity and Parental leaves

- Mobile services subsidy

- Sick pay-Life insurance

- CI&T University   

- Colombian Holidays

- Paid Vacations

And many others. 



CI&T is an equal-opportunity employer. We celebrate and appreciate the diversity of our CI&Ters’ identities and lived experiences. We are committed to building, promoting, and retaining a diverse, inclusive, and equitable company and culture focused on creating a better tomorrow.


At CI&T, we recognize that innovation and transformation only happen in diverse, inclusive, and safe work environments. Our teams are most impactful when people from all backgrounds and experiences collaborate to share, create, and hear ideas.


Before applying for our opportunities take a look at Conflict of Interest Policy on website.


We strongly encourage candidates from diverse and underrepresented communities to apply for our vacancies.

What You Should Know About [Job-19070] Architect (Security & DevSecOps Support), Colombia, CI&T

Are you ready to step into a pivotal role as an Architect in Security & DevSecOps Support at CI&T? Here at CI&T, we pride ourselves on being tech transformation specialists, weaving the power of Artificial Intelligence with human expertise to guide large companies through technological shifts. With three decades of experience and a global team of 6,000 talents across five continents, we help clients unlock the potential of technology to create meaningful impacts. In this position, you will enhance the security posture of our development pipelines and frameworks, working to design and implement secure Continuous Integration and Continuous Deployment (CI/CD) processes. You will partner with engineering teams to cultivate a culture of security awareness and optimal DevSecOps practices. Your key responsibilities will include designing secure CI/CD pipelines, conducting security assessments, and assisting with the automation of security testing within the CI/CD pipeline. Naturally, a solid understanding of software development processes and familiarity with CI/CD tools will be vital for your success. You’ll be expected to stay ahead of the curve with the latest trends in security and DevSecOps. If you’re passionate about marrying security with technology while working in a diverse and inclusive environment, this role at CI&T could be your next career adventure. Join us to make a difference and help create a better tomorrow!

Frequently Asked Questions (FAQs) for [Job-19070] Architect (Security & DevSecOps Support), Colombia Role at CI&T
What are the responsibilities of an Architect in Security & DevSecOps Support at CI&T?

In the role of an Architect in Security & DevSecOps Support at CI&T, your main responsibilities include designing secure CI/CD pipelines, collaborating with cross-functional teams to optimize DevSecOps practices, and participating in security assessments of CI/CD processes. You'll also assist in the development of security frameworks and guidelines while helping to identify vulnerabilities and recommend strategies for mitigation.

Join Rise to see the full answer
What qualifications are needed for the Architect in Security & DevSecOps Support position at CI&T?

To qualify for the Architect in Security & DevSecOps Support position at CI&T, candidates should have a solid understanding of software development methods, familiarity with CI/CD tools like Jenkins or GitLab, and knowledge of security principles including application and cloud security. Proficiency in scripting languages like Python or Bash, alongside familiarity with containerization technologies such as Docker, is highly valued.

Join Rise to see the full answer
What tools do Architects in Security & DevSecOps Support at CI&T use frequently?

Architects in Security & DevSecOps Support at CI&T frequently use CI/CD tools such as Jenkins, CircleCI, and GitLab CI. They also often work with security tools for vulnerability scanning and conduct assessments as part of their responsibilities to ensure security is embedded within development processes.

Join Rise to see the full answer
How does CI&T promote continuous learning for Architects in Security & DevSecOps Support?

CI&T is committed to continuous learning for all its employees, including Architects in Security & DevSecOps Support. Through initiatives such as CI&T University, team members are provided with opportunities to evolve their skills, stay informed about emerging technologies in security and DevSecOps, and keep their knowledge current in this ever-evolving field.

Join Rise to see the full answer
What types of security assessments might an Architect in Security & DevSecOps Support conduct at CI&T?

An Architect in Security & DevSecOps Support at CI&T might conduct various security assessments including audits of CI/CD tools and processes, vulnerability assessments of applications, and compliance checks within the development pipeline to ensure all security practices are being adhered to.

Join Rise to see the full answer
Common Interview Questions for [Job-19070] Architect (Security & DevSecOps Support), Colombia
Can you explain what a CI/CD pipeline is and its importance in development?

A CI/CD pipeline is a set of automated processes that allow developers to integrate changes into the codebase and deploy those changes quickly and reliably. Its significance lies in its ability to accelerate development cycles while ensuring that code remains tested and secure throughout the process.

Join Rise to see the full answer
How do you integrate security into the CI/CD pipeline?

Integrating security into the CI/CD pipeline involves implementing security best practices at every stage of the development lifecycle. This includes automated security testing, code analysis during the build phase, and compliance checks before deployment. It's crucial to foster a culture of security awareness among development teams.

Join Rise to see the full answer
What experience do you have with containerization and orchestration technologies?

I have hands-on experience with containerization platforms like Docker, along with orchestrators such as Kubernetes. This experience includes deploying secure applications in containers, managing deployments, and scaling applications effectively while maintaining a focus on security.

Join Rise to see the full answer
What security tools have you worked with that relate to DevSecOps practices?

I have worked with various security tools, including vulnerability scanners to identify weaknesses in applications, static and dynamic code analysis tools to enforce coding standards, and automation scripts for running security assessments as part of the CI/CD pipeline.

Join Rise to see the full answer
How do you ensure compliance with security frameworks in your projects?

Ensuring compliance with security frameworks involves understanding the requirements of frameworks like GDPR or HIPAA and implementing controls and practices that satisfy those requirements. Regular audits, risk assessments, and team training are also crucial to maintain compliance.

Join Rise to see the full answer
Describe a time when you identified a security vulnerability during a project.

In a previous project, I discovered a significant vulnerability in a web application during a security assessment. I collaborated with the development team to create a patch, documented the process, and established a set of best practices to prevent similar issues in the future.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity trends?

I stay updated with the latest cybersecurity trends by following industry-leading blogs, participating in webinars, engaging in online communities, and pursuing continual education through certifications and workshops to deepen my knowledge and skills.

Join Rise to see the full answer
What role do you think collaboration plays in successful DevSecOps practices?

Collaboration is key in DevSecOps as it fosters a shared responsibility for security across development, operations, and security teams. When teams work together effectively, they can build security into the development process, streamline communication, and enhance overall project outcomes.

Join Rise to see the full answer
Can you provide an example of how you automated security in CI/CD pipelines?

In my previous role, I automated security testing in CI/CD pipelines by integrating security scanning tools into our build process. This allowed us to catch vulnerabilities early, triggered alerts on failures, and provided developers with immediate feedback to address issues quickly.

Join Rise to see the full answer
What do you believe is the most significant challenge in DevSecOps?

One of the most significant challenges in DevSecOps is balancing speed and security. As organizations strive for quicker releases, integrating security without slowing down the development process requires strategic planning, stakeholder buy-in, and effective tooling to achieve optimal workflows.

Join Rise to see the full answer

CIT Group Inc. operates as the bank holding company for CIT Bank, National Association that provides banking and related services to commercial and individual customers. The company operates through Commercial Banking, Consumer Banking, Non-Strate...

22 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 7, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!