Principal Software Engineer – DevSecOps

7 Hours ago • All levels • Devops

Job Summary

Job Description

Boomi is seeking a Principal Software Engineer specializing in DevSecOps to join their fast-growing company. The role involves enhancing the security posture of cloud environments, particularly AWS and Azure, through the implementation and management of security services, IAM roles, and policies. The engineer will be responsible for developing and maintaining infrastructure using Infrastructure as Code (IaC) tools like Terraform and CloudFormation, and automating security configurations and compliance checks. A key aspect of the role includes integrating security controls into CI/CD pipelines using tools such as Jenkins and Azure DevOps, and automating static and dynamic code analysis. The position also requires setting up monitoring and alerting systems, developing incident response plans, and ensuring compliance with industry standards like ISO 27001 and SOC 2. Collaboration with development, operations, and security teams to foster a security-conscious culture is essential, along with providing training on secure practices.
Must have:
  • AWS IAM roles, policies, and permissions management
  • Azure Active Directory (AAD) and RBAC for access management
  • Infrastructure as Code (IaC) with Terraform/CloudFormation
  • CI/CD security integration (SAST/DAST)
  • Monitoring and alerting with CloudWatch/Azure Monitor
  • Vulnerability management with Snyk/TruffleHog
  • Secure coding practices (OWASP Top 10)
  • Threat modeling (STRIDE/DREAD)
Good to have:
  • AWS security services (Config, CloudTrail, GuardDuty)
  • Azure Security Center and Azure Policy
  • Secrets management (AWS Secrets Manager, Azure Key Vault, Vault)
  • Container security (Docker, Kubernetes)
  • Compliance standards (ISO 27001, SOC 2, PCI DSS, HIPAA)
  • Cryptography fundamentals
  • OAuth 2.0, OpenID Connect, SSO
Perks:
  • Work with world-class people
  • Work with industry-leading technology
  • Build something big
  • Inclusive and accessible environment

Job Details

About Boomi and What Makes Us Special

Are you ready to work at a fast-growing company where you can make a difference? Boomi aims to make the world a better place by connecting everyone to everything, anywhere. Our award-winning, intelligent integration and automation platform helps organizations power the future of business. At Boomi, you’ll work with world-class people and industry-leading technology. We hire trailblazers with an entrepreneurial spirit who can solve challenging problems, make a real impact, and want to be part of building something big. If this sounds like a good fit for you, check out boomi.com  or visit our Boomi Careers page to learn more.

Role and Responsibilities

  • AWS Security and IAM:

    • Extensive experience in managing AWS IAM roles, policies, and permissions, ensuring adherence to the principle of least privilege.

    • Proficiency in utilizing AWS security services such as AWS Config, CloudTrail, GuardDuty, and Security Hub for continuous monitoring and compliance.

    • Hands-on experience with AWS Key Management Service (KMS) for encryption key management and data protection.

  • Azure Security and Identity Management:

    • Solid understanding of Azure Active Directory (AAD) for identity and access management across Azure resources.

    • Experience with Azure Role-Based Access Control (RBAC) to manage permissions and access to Azure services.

    • Familiarity with Azure Security Center and Azure Policy for assessing and improving the security posture of Azure environments.LinkedIn+3careers-buspatrol.icims.com+3SmartRecruiters+3

  • Infrastructure as Code (IaC) and Automation:

    • Proficient in developing and maintaining infrastructure using IaC tools such as Terraform, AWS CloudFormation, and Azure Resource Manager (ARM) templates.

    • Experience in automating security configurations and compliance checks across AWS and Azure environments.

    • Skilled in implementing and managing secrets management solutions like AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault.

  • CI/CD Pipeline Security Integration:

    • Expertise in integrating security controls and checks into CI/CD pipelines using tools like Jenkins, GitLab CI/CD, Azure DevOps, or AWS CodePipeline.

    • Experience in automating static and dynamic code analysis (SAST/DAST) to identify and remediate vulnerabilities early in the development lifecycle.

    • Familiarity with containerization and orchestration tools like Docker and Kubernetes, including implementing security best practices.

  • Monitoring and Incident Response:

    • Proficient in setting up and maintaining monitoring and alerting systems using AWS CloudWatch, Azure Monitor, and third-party SIEM tools.

    • Experience in developing incident response plans and conducting regular drills to ensure preparedness for security events.

    • Skilled in conducting root cause analysis and implementing corrective actions to prevent future incidents.

  • Compliance and Governance:

    • Thorough understanding of industry standards and frameworks such as ISO 27001, SOC 2, PCI DSS, and HIPAA.

    • Experience in maintaining documentation for security policies, procedures, and compliance audits.

    • Stay updated on emerging security threats and cloud security features to proactively address potential risks.

  • Vulnerability Management:

    • Hands-on experience with vulnerability assessment tools like Snyk, TruffleHog, and CrowdStrike CSPM to identify and remediate security issues.

    • Ability to prioritize and track remediation efforts to ensure timely resolution of vulnerabilities.

  • Collaboration and Training:

    • Proven ability to work closely with development, operations, and security teams to promote a culture of security and shared responsibility.

    • Experience in providing training and guidance on secure coding practices, cloud security, and DevSecOps methodologies.

 

Technical Must-Know Concepts

  • Application Security:

    • In-depth knowledge of secure coding practices, including familiarity with OWASP Top 10 and CWE guidelines.

    • Experience integrating security into the Software Development Life Cycle (SDLC).

  • Threat Modeling:

    • Proficiency in threat modeling methodologies such as STRIDE and DREAD.

    • Ability to identify attack surfaces and develop mitigation strategies.

  • Cloud Security:

    • Expertise in AWS and Azure security best practices, including IAM, KMS, GuardDuty, and Security Center.

    • Understanding of encryption mechanisms for data at rest and in transit.

    • Experience in hardening cloud resources to prevent unauthorized access.

  • Infrastructure and CI/CD Security:

    • Knowledge of securing Infrastructure as Code (IaC) using tools like Terraform and CloudFormation.

    • Experience with secrets management and integrating security scans (SAST, SCA, DAST) into CI/CD pipelines.

  • Vulnerability Management:

    • Proficiency in using tools like Snyk, TruffleHog, and CrowdStrike CSPM for vulnerability assessment.

    • Ability to prioritize vulnerabilities based on risk and impact.

  • Authentication and Authorization Security:

    • Understanding of OAuth 2.0, OpenID Connect, and Single Sign-On (SSO) principles.

    • Experience in implementing secure authentication and authorization mechanisms.

  • Container and Kubernetes Security:

    • Knowledge of container security best practices, including image scanning and hardening.

    • Experience with Kubernetes security features like RBAC and network policies.

  • Cryptography Fundamentals:

    • Familiarity with TLS/SSL protocols, encryption standards, and key management practices.

  • Security Standards and Compliance:

    • Awareness of frameworks such as NIST, ISO 27001, SOC 2, and PCI DSS.

    • Experience in aligning security practices with compliance requirements.

  • DevSecOps Tooling:

    • Proficiency in using CI/CD tools like GitHub, GitLab, and Bitbucket, and integrating security automation into workflows.

 

Be Bold. Be You. Be Boomi. We take pride in our culture and core values and are committed to being a place where everyone can be their true, authentic self. Our team members are our most valuable resources, and we look for and encourage diversity in backgrounds, thoughts, life experiences, knowledge, and capabilities.  

All employment decisions are based on business needs, job requirements, and individual qualifications.

Boomi strives to create an inclusive and accessible environment for candidates and employees. If you need accommodation during the application or interview process, please submit a request to talent@boomi.com. This inbox is strictly for accommodations, please do not send resumes or general inquiries. 

Similar Jobs

Glocomms - Director, Application Security Architecture

Glocomms

Tampa, Florida, United States (Hybrid)
1 Month ago
Nice - Principal Client Services Program Manager, Actimize

Nice

London, England, United Kingdom (Hybrid)
16 Hours ago
New Globe - Front-end Engineer

New Globe

Porto, Porto District, Portugal (Remote)
2 Weeks ago
Maxis Studios - Senior Software Engineer - C#

Maxis Studios

Bogota, Colombia (On-Site)
2 Months ago
gitlab - Strategic Account Executive

gitlab

Mumbai, Maharashtra, India (Remote)
13 Hours ago
Unisys - Presales Solution Architect

Unisys

Hungary (On-Site)
1 Month ago
Veeam Software - Devops Engineer

Veeam Software

Prague, Czechia (Hybrid)
2 Weeks ago
Egnyte - Junior Site Reliability Engineer

Egnyte

Mumbai, Maharashtra, India (On-Site)
3 Weeks ago
Mashgin - Deployment Engineer

Mashgin

Los Angeles, California, United States (Remote)
2 Years ago
Canva - Staff Frontend Engineer - Apps API Platform

Canva

Melbourne, Victoria, Australia (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

London stock Exchange - Technical Lead

London stock Exchange

Hyderabad, Telangana, India (On-Site)
1 Month ago
gitlab - Public Sector Solutions Architect

gitlab

United States (Remote)
1 Month ago
Capgemini - Business Analyst_Retail (CPR) Consulting

Capgemini

Pune, Maharashtra, India (On-Site)
1 Month ago
NVIDIA - Engineering Farm Engineer

NVIDIA

Bengaluru, Karnataka, India (On-Site)
2 Months ago
gitlab - Customer Success Manager

gitlab

United States (Remote)
13 Hours ago
GoTo Group - Senior SDET - DPI

GoTo Group

Bengaluru, Karnataka, India (Hybrid)
2 Weeks ago
GHX - Software Engineer III

GHX

Hyderabad, Telangana, India (On-Site)
13 Hours ago
gitlab - Senior Product Manager, Tenant Scale

gitlab

(Remote)
1 Month ago
Zones - Business Systems Analyst - Sales

Zones

Lahore, Punjab, Pakistan (On-Site)
1 Year ago

Get notifed when new similar jobs are uploaded

Jobs in India

Deutsche Bank - Confirmations Analyst

Deutsche Bank

Bengaluru, Karnataka, India (Hybrid)
9 Months ago
CME Group - Software Engineer II

CME Group

Bengaluru, Karnataka, India (On-Site)
1 Year ago
Believe - Business Operations Analyst - Finance Operations

Believe

Mumbai, Maharashtra, India (On-Site)
1 Week ago
Ion - Principal Technical Consultant - Openlink

Ion

Noida, Uttar Pradesh, India (On-Site)
1 Year ago
Boomi  - Customer Success Analyst - Sr Advisor

Boomi

Bengaluru, Karnataka, India (On-Site)
1 Month ago
smarsh - Cloud Engineer III-Observability

smarsh

India (Hybrid)
5 Months ago
ISS Stoxx - Data Analyst

ISS Stoxx

Mumbai, Maharashtra, India (On-Site)
1 Month ago
Nagarro - Engineer ,SAP Govern Risk Compliance

Nagarro

India (Remote)
8 Months ago
Nagarro - Senior Staff Engineer, ETL

Nagarro

India (Remote)
8 Months ago
Contentstack - Senior Engineer I - QA (Playwright and Selenium)

Contentstack

Pune, Maharashtra, India (Hybrid)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Devops Jobs

Rackspace Technology - Senior DevOps Engineer (AWS)

Rackspace Technology

Germany (Remote)
2 Months ago
Zazz - Cloud Engineer (AWS)

Zazz

(Remote)
4 Months ago
Volley that - Staff Infrastructure Engineer

Volley that

San Francisco, California, United States (Hybrid)
1 Month ago
GoReel - DevOps Lead

GoReel

Bratislava Region, Slovakia (Remote)
3 Months ago
Sony Interactive Entertainment - Software Engineer (Automation Framework Development)

Sony Interactive Entertainment

Tokyo, Japan (On-Site)
2 Months ago
CyberArk - Senior Site Reliability Engineer

CyberArk

United States (Remote)
1 Month ago
Epic Games - Senior Programmer, Development and Operations (DevOps)

Epic Games

Montreal, Quebec, Canada (On-Site)
2 Months ago
Poppulo - Senior Software Engineer – Backend & Cloud (TypeScript)

Poppulo

Bengaluru, Karnataka, India (Hybrid)
4 Weeks ago
Qualcomm - Senior Software Developer - AI DevOps Engineer

Qualcomm

San Diego, California, United States (On-Site)
2 Weeks ago
Anavation - Cloud Engineer

Anavation

Reston, Virginia, United States (On-Site)
3 Weeks ago

Get notifed when new similar jobs are uploaded

About The Company

At Boomi, we believe in accountability and transparency, and proudly enable innovation. When you work at Boomi, you can be your true, authentic self in our unique, independent culture. Be boldWe take ownership of our work and results, continuously improve, exceed expectations, stay curious, and create for the future while learning from the past. Be youWe build authentic relationships, lead with integrity, and bring our whole selves to our work and interactions with customers, partners, and communities.
View All Jobs

Get notified when new jobs are added by Boomi

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug