The Role
We are looking for a highly motivated, self-sufficient and talented Operations Security Lead who can help build out a nascent Secure-by-default Operations Security strategy. We are looking for an innovator who strives to continuously iterate, improve and learn. The Security team at Nitro focuses on partnering with engineering groups throughout the company to create and deliver applications and services that are secure. Our work includes audits such as operations and infrastructure reviews, threat models and architecture reviews. We also build partnerships with our corporate IT team in defining security-related requirements and providing input on infrastructure and operations proposals. The team will also create tools and practices which will allow us to scale our work to cover a diverse and complex set of services across the broader organization.
What You Will Be Doing
- Assess the current state of Operations Security and set a high bar for the development of a scalable, secure-by-default OpSec strategy
- Contribute to the design of a Zero Trust corporate environment strategy
- Perform reviews ranging from architectural design to operations and cloud-based infrastructure reviews, providing actionable recommendations to make Nitro’s product, service and corporate infra environments more secure
- Help design and develop logging and monitoring operations improvements to scale security visibility and insight across the broader organization
- Help build solutions to secure and transfer valuable data through Nitro’s systems and services
- Be available on call to triage and respond to security alerts and potential incidents
- Provide technical leadership to junior members of the security organization
- Five + years of experience in the Operations security space, including experience securing Cloud infrastructures (AWS, Azure, etc.)
- Hands-on experience with securing Containers/Kubernetes
- Hands-on experience writing code for security tooling and automation
- Strong security fundamentals knowledge and solid threat modelling and security architecture skills
- Experience utilizing infrastructure as code tools like Terraform
- A track record of contributing to projects from design to implementation and through maintenance
- Experience helping to design or improve security logging and monitoring strategies, including experience with modern observability platforms (like DataDog)
- Practical knowledge and experience working in public cloud environments (AWS, Azure, etc.)
- An interest in conceiving and building creative solutions to complex security problems and scaling the team’s impact through DevSecOps solutions