Senior Specialist, Information Security DevSecOps

2 weeks ago


Boise, United States Planned Parenthood Federation of America Full time

Planned Parenthood is the nation's leading provider and advocate of high-quality, affordable sexual and reproductive health care for all people, as well as the nation's largest provider of sex education. With more than 600 health centers across the country, Planned Parenthood organizations serve all patients with care and compassion, with respect, and without judgment, striving to create equitable access to health care. Through health centers, programs in schools and communities, and online resources, Planned Parenthood is a trusted source of reliable education and information that allows people to make informed health decisions. We do all this because we care passionately about helping people lead healthier lives.


Planned Parenthood Federation of America (PPFA) is a 501(c)(3) charitable organization that supports the independently incorporated Planned Parenthood affiliates operating health centers across the U.S. Planned Parenthood Action Fund is an independent, nonpartisan, not-for-profit membership organization formed as the advocacy and political arm of Planned Parenthood Federation of America. The Action Fund engages in educational, advocacy, and electoral activity, including grassroots organizing, legislative advocacy, and voter education.


Planned Parenthood Federation of America (PPFA) and Planned Parenthood Action Fund (PPAF) seeks a dynamic and effective Senior Specialist DevSecOps Architecture and Engineering. This job reports directly to the Director, DevSecOps Architecture & Engineering in the Information Security division of PPFA. The Office of Information Security provides the strategy and implementation of the information security program that safeguards the data entrusted to Planned Parenthood by its patients, supporters, donors and staff.


Purpose:

As a Senior Specialist DevSecOps Architecture and Engineering, you will work within a multi-disciplined team to provide expertise on complex systems. You'll stay up-to-date with the latest Continuous Integration/Continuous Deployment (CI/CD) security standards, systems, and authentication protocols, as well as best practice security products. You'll foster trusted partnerships and relationships with the Digital Products, DevOps, AppDev, and ITOps teams. This will require you to understand the business, its digital strategy, and have a comprehensive awareness of its technology and information needs. You'll ultimately use this knowledge to develop and test security controls, protecting the development pipeline and supporting systems.


Security Integration: Emphasize integrating security seamlessly throughout the software development lifecycle (SDLC). This includes tasks like threat modeling, vulnerability scanning, and secure coding practices.


Automation: Highlight the engineer's responsibility for automating security processes to improve efficiency and reduce manual errors.


Collaboration: Stress the importance of collaboration with developers, security professionals, and operations teams to foster a shared security culture.


Compliance: Mention ensuring adherence to security standards and regulations relevant to your industry and organization.


Delivery:

Design, build, and manage a scalable threat modeling framework, leveraging automation to integrate application security into the CI/CD pipeline, and act as the product owner of application security automation platform.


Work directly with project development teams and ITOps to enable successful project implementation applying the recommended security tools, technologies, and techniques. Provide expertise to project team engineers and architecture as needed.


Stay up to date on new tools & techniques in the information security space.


Support an information security solution that is scalable and easy to adapt with changing business requirements.


Support DevSecOps security solution integration with various security test tools.


Assets with programmatic code review and penetration test applications to decrease potential introduction of vulnerabilities within the code.


Contribute to vulnerability detection and remediation of technological offerings.


Educating other team members on application security standards and best practices.


Participating in enterprise technology and functional planning processes to develop standards and best practices.


Support engineering and development direction for application security designs that solve business problems.


Experience working with container security.


Support DevSecOps security integration with various security testing tools.


Working with application teams and ITOps on security solution design and implementation.


Participate in DevSecOps security solutions, and proof of concepts.


Support cross functional team members on DevSecOps standards and best practices.


Participating in enterprise technology and functional planning processes to develop standards and best practices.


Support building, deploying, and maintaining instrumentation and security controls in and around code.


Support programmatic code review and penetration test applications to decrease potential introduction of vulnerabilities within the code.


Engagement:

Engage with Digital Products, Applications Development, and senior-level staff within PPFA.


Provide technical thought leadership in overall security Solution development.


Works closely with other technical teams including the ITOps and DevSecOps Architecture and Engineering.

A solid understanding of industry-standard scanning tools including Venari, Fortify on Demand, and ZAProxy.


Work closely with the application development and infrastructure architectural teams to create secure code by design and default.


Work with DevSecOps to implement automated security testing tools (SAST, DAST) within the CI/CD pipeline, catching potential threats before deployment.


Work closely DevSecOps to establish prevention, detection, and mitigation techniques.


Collaborate with AI Community, InfoSec, and Office of General Counsel (OGC).


Knowledge, Skills, and Abilities (KSAs):

You will report to the Director of DevSecOps Architecture and Engineering and will work closely with Digital Products, Application Development, DevSecOps, and ITOps.


Technical bachelor's degree and 3 + years of industry experience or equivalent work experience.


2 + years of experience working with container security solutions.


At least 2 years of experience implementing DevOps tool-chain (Jenkins, SonarQube, GitHub, Nexus, Code quality tools) implementation and automation.


Minimum 3 years of experience with scripting and automation.


Minimum 3 years of experience with web application and web service implementation.


Hands-on experience with application development is required.


Hands-on experience with GenAI systems is preferred.


Expert knowledge of the OWASP framework and application security best practices.


Passion to work on newer technologies and explore the security domain.


Experience in compliance requirements and industry standards PCI-DSS, HIPAA, ISO 27001, NIST, CSF, ITIL, COBIT, Sarbanes Oxley, and SANS 20.


ML Sec Ops and Prompt Injection Testing.


TRAVEL: Up to 10% travel on occasion


Total offer package to include generous vacation + sick leave + paid holidays, individual/family provided medical, dental and vision benefits effective day 1, life insurance, short/long term disability, paid family leave and 401k. We also offer voluntary opt-in for Flexible Spending Account (FSA) and Transportation/Commuter accounts.


We value a truly diverse workforce and a culture of inclusivity and belonging. Our goal is to attract qualified candidates and encourage applications from all individuals without regard to race, color, religion, sex, national origin, age, disability, veteran status, marital status, sexual orientation, gender identity, or any other characteristic protected by applicable law. We're committed to creating a dynamic work environment that values diversity and inclusion, respect and integrity, customer focus, and innovation.


PPFA participates in the E-Verify program and is an Equal Opportunity Employer.


#LI-SY1

*PDN-HR


Roles that are denoted as NYC, DC, or both will work a hybrid schedule, requiring 2-3 days per week in the office unless the role is denoted as onsite, which requires working onsite full time or 5 days per week.

PDN-9bbd50c9-238d-410f-b71e-0e798ac38873
  • Security Specialist

    5 days ago


    Boise, Idaho, United States Security Industry Specialists Full time

    About this position:Department: Retail SecurityLocation: Boise, IDEmployment Type: Part-time/FlexibleAbout us:Security Industry Specialists, Inc. (SIS) is a leading provider of security solutions to top companies and brands worldwide. We deliver exceptional services that exceed industry standards through innovation, continuous improvement, and a commitment...


  • Boise, Idaho, United States Securitas Security Services USA Full time

    Position: Site Security SpecialistEmployment Type: Full TimeLocation: Boise, IDCompensation: $18.50 - $19.50 per hourAt Securitas Security Services USA, we operate across numerous markets, providing a comprehensive range of security solutions from traditional guarding to advanced technology-driven security measures.As a Site Security Specialist, you will be...

  • Security Specialist

    2 weeks ago


    Boise, Idaho, United States Garda World Security Full time

    Job OverviewGardaWorld –Security ServicesPosition: Security Specialist – Join Our TeamAt GardaWorld, we recognize that you possess the necessary skills, and we are here to provide you with the right opportunity to realize your potential. Our organization is currently expanding, and we are looking for dedicated individuals to join our team.Every day at...


  • Boise, Idaho, United States Sloan Security Group Full time

    Job SummaryThe Sloan Security Group is seeking a highly skilled Barrier Security Specialist to join our team. As a key member of our security team, you will be responsible for the installation, maintenance, and repair of various security-related equipment, including vehicle barriers, operated bollards, and gates.Key ResponsibilitiesCustomer Support: Provide...

  • Senior Manager

    1 week ago


    Boise, United States Marriott Full time

    Job Number 24150925 Job Category Information Technology Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States Schedule Full-Time Located Remotely? Y Relocation? N Position Type Management JOB SUMMARY The Senior Manager is responsible for leading and coordinating, articulating, and tracking actions related to developing...


  • Boise, Idaho, United States Sloan Security Group Full time

    Job SummaryThe Low Voltage Security Systems Specialist is a key member of the Sloan Security Group team, responsible for the installation, service, maintenance, warranty, and repair of various security-related equipment. This role requires a strong technical background in electronic security and network systems, as well as excellent problem-solving and...


  • Boise, United States Marriott Full time

    Job Number 24121526 Job Category Information Technology Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States Schedule Full-Time Located Remotely? Y Relocation? N Position Type Management JOB SUMMARY This position will be part of the Cloud Security Engineering Team within the Global Information Security organization....


  • Boise, Idaho, United States Army National Guard Units Full time

    Position OverviewThis role is designated for an IT SPECIALIST (SYSADMIN/CUSTSPT) within the Army National Guard Units. This position is essential for maintaining operational efficiency and ensuring the smooth functioning of IT systems.Key Responsibilities1. Utilizes comprehensive knowledge of logistics operations and automated systems to oversee projects...


  • Boise, Idaho, United States Army National Guard Units Full time

    Position OverviewThis role is for an IT SPECIALIST (SYSADMIN/CUSTSPT) within the Army National Guard Units. The incumbent will provide critical support and maintenance for automated logistics information systems.Key Responsibilities1. Leverage comprehensive knowledge of logistics operations and automated systems to oversee projects related to systems...


  • Boise, Idaho, United States Signal Security Full time

    Job Summary:Signal Security is seeking a highly skilled and dedicated Security Officer to conduct static security services for courtyards, offices, pools, and other high-value areas. As a Security Officer, you will be responsible for ensuring all required access points are properly secured and protecting property and residents with a high degree of...


  • Boise, Idaho, United States Micron Technology Full time

    About the RoleMicron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.This role operates out of the Global Quality Management Office (GQMO) and is responsible for the development of the product...


  • Boise, United States Idaho Probation and Pretrial Services Full time

    Main content Job Details for Information Technology Specialist Court Name/Organization: Idaho Probation and Pretrial Services Overview of the Position: The U.S. Probation and Pretrial Services Office for the District of Idaho is accepting applications for the position of Information Technology Specialist. This position will be located in the United...

  • Security Specialist

    2 weeks ago


    Boise, Idaho, United States GardaWorld Full time

    Job Overview GardaWorld - Security Services Security Specialist - Now Hiring 2 years experience required. At GardaWorld, we recognize that having the right skills is essential, but what truly matters is finding the right opportunity to realize your potential. We are currently expanding our team and looking for dedicated individuals. Every day presents new...


  • Boise, Idaho, United States Transportation Safety Administration Full time

    LocationBoise, IdahoKey ResponsibilitiesOverviewSecurity Operations Specialists play a crucial role in ensuring the safety and security of passengers across various transportation modalities. Their responsibilities may also encompass the safeguarding of significant events, prominent individuals, and any elements that influence our transportation...


  • Boise, Idaho, United States Boise State University Full time

    Position Overview:As a Lead Security Specialist, you will play a crucial role in safeguarding the safety and security of our community, including residents, staff, and facilities. Your responsibilities will encompass responding to emergencies, managing safety protocols, and performing related duties to ensure a secure environment.Department Insight:At Boise...


  • Boise, United States Marriott Full time

    Job Number 24103262 Job Category Information Technology Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States Schedule Full-Time Located Remotely? Y Relocation? N Position Type Management JOB SUMMARY The Manager, Vulnerability Management functions as a technical expert in the areas of vulnerability scanning and...


  • Boise, Idaho, United States Humana Full time

    Join a mission-driven organization focused on health and well-beingHumana is looking for a Senior Executive Talent Acquisition Specialist to collaborate with top executives in securing exceptional talent for critical leadership positions, particularly at the SVP and VP levels, including confidential roles.The Executive Talent Acquisition Specialist will take...


  • Boise, Idaho, United States State of Idaho Full time

    State of Idaho The State of Idaho is looking for a dedicated Senior Procurement Specialist. This role is essential for our operational efficiency and will involve collaborating with various departments to ensure effective purchasing practices. About the State of Idaho: Join a team of professionals committed to managing and safeguarding Idaho's natural...


  • Boise, Idaho, United States Army National Guard Units Full time

    Position OverviewThis position is for an IT Specialist (Systems Administrator/Customer Support) within the Army National Guard Units. The role involves critical responsibilities in managing and supporting automated logistics systems.Key Responsibilities1. Leverage extensive knowledge of logistics operations and automated systems to oversee projects related...


  • Boise, Idaho, United States Scandinavian Designs Furniture Full time

    Role OverviewAs a Senior Procurement Specialist, you will play a pivotal role in leading a dynamic team focused on procurement, product sourcing, and vendor relations that drive and elevate our business objectives.Key ResponsibilitiesStrategic Development: Formulate and execute comprehensive strategies for product assortment that align with market dynamics...