DevSecOps Engineer (US)

Posted:
8/20/2024, 5:00:00 PM

Location(s):
Florida, United States ⋅ Fort Lauderdale, Florida, United States ⋅ New Jersey, United States

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
DevOps & Infrastructure ⋅ IT & Security

Work Location:

United States of America

Hours:

40

Pay Details:

$87,000 - $151,000 USD

TD is committed to providing fair and equitable compensation opportunities to all colleagues. The included salary range for this role takes into account multiple factors that are considered in making compensation decisions. The base pay actually offered may vary based upon candidate's skills and experience, job-related knowledge, licensure and certifications, geographic location, and other specific business and organizational needs. As TD puts career development at the forefront of our colleague experience, it is not typical for an individual to be hired at or near the top of the range for their role.

As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.

Line of Business:

Technology Solutions

Job Description:

The DevSecOps engineer is an Engineering II role to help support, secure, manage and deploy solutions that support TD Bank's software delivery initiatives. The role is highly technical, and candidates must possess a solid understanding of information security, cloud infrastructure, software, and various reference architectures. The role also requires an understanding of clients' business goals, product strategy and operational requirements in a highly secured/governed environment. The DevSecOps engineer supports continuous integration and continuous deployment (CI/CD) initiatives and is an integrated team member working with software developers, product engineers, cybersecurity engineers and systems administrators. The DevSecOps engineer acts as a liaison with business stakeholders to understand the strategy and execution outlook. The role is heavily security-focused and ingrained in the CI/CD pipeline automation to deliver security and privacy by design principles and validation throughout the software lifecycle.

DevSecOps engineers have a strong work ethic, perform analytical and critical thinking, and are masterful at meeting change requests on demand. They are expected to work well with business units and possess superior listening and communication skills, in addition to expected technical expertise. DevSecOps engineers embody security-first principles, constantly assess the threat landscape, and adapt quickly to manage enterprise risk, as well as integration, configuration, and deployment requirements.

  • Build relationships with developers, stakeholders, and pod leaders to incorporate security principles into engineering design and deployments.
  • Implementation, testing and validation of application security controls across projects through automation workflows in CI/CD.
  • Implementation of defensive configurations and countermeasures across cloud infrastructure and applications.
  • Recommend services and tools to enable developers and engineers to easily use security components produced by application security team members.
  • Simplify automation that applies security inter-workings with CI/CD pipelines.
  • Support the ability to “shift left” and incorporate security early on and throughout the development lifecycle including threat modeling and developer IDE security features.
  • Assist prioritization of vulnerabilities identified in code through automated and manual assessments and promote quick remediation.
  • Join forces and provision security principles in architecture, infrastructure, and code.
  • Regularly research and learn new tactics, techniques and procedures in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary through the CI/CD pipeline.
  • Enrich DevOps architecture with security standards and best practices, promote baseline configuration and work to reduce drift.
  • Partner with teams to define key performance indicators (KPIs), key risk indicators (KRIs) and distribute useful program metrics across business units.
  • Perform other duties as assigned.

Depth & Scope:

  • Expert knowledge of specific domain or range of engineering frameworks, technology, tools, processes and procedures, as well as organization issues
  • Expert knowledge of TD applications, systems, networks, innovation, design activities, best practices, business/organization, Bank standards, and may fulfill a governance role
  • Expert knowledge and experience in own discipline; integrates knowledge of business and functional priorities
  • Acts as a key contributor in a complex and critical environment
  • May provide leadership to teams or projects; shares expertise
  • Applies in-depth skills and broad knowledge of the business to address complex problems and non-standard situations


Education & Experience:

  • Bachelor's or Graduate degree
  • Strong academic background (e.g., computer science, engineering)
  • 7 + years relevant experience

Preferred Qualifications:

  • Experience working with development and infrastructure teams in agile workflows, including Scrum and Kanban.
  • Understanding of containerized compute (e.g., Docker) and container orchestration (e.g., Kubernetes)
  • Experience with Nexus IQ, GitHub Advanced Security, SonarQube, Terraform, Jenkins, and Ansible.
  • Experience with operations and security across Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP).
  • Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface while performing rapid, continuous testing and implementation.
  • Capable of scripting in Python, Bash and PowerShell.
  • Understanding of the software development lifecycle (SLDC) and how to balance the recommendations of each against business priorities and security requirements.
  • Knowledge of Supply-chain Levels for Software Artifacts (SLSA), Payment Card Industry (PCI), National Institute of Standards (NIST) or Center for Internet Security (CIS) control requirements a plus.

Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues. 

TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you’ve got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we’re here to support you towards your goals. As an organization, we keep growing – and so will you.

Our Total Rewards Package


Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including Vacation PTO, Flex PTO, and Holiday PTO), banking benefits and discounts, career development, and reward and recognition. Learn more

Additional Information:
We’re delighted that you’re considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we’re committed to providing the support our colleagues need to thrive both at work and at home.

Colleague Development
If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.

Training & Onboarding
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.

Interview Process
We’ll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.

Accommodation

If you are an applicant with a disability and need accommodations to complete the application process, email the TD Bank US Workplace Accommodations Program at [email protected]. Include your full name, best way to reach you, and the accommodation needed to assist you with the application process.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.