PG
Senior IT Risk & DevSecOps Analyst
Perfict Global, Inc.
Location not stated
Remote
Senior
1 month ago
- DevSecOps
- CI/CD
- AI
- Risk Management
- Azure Cloud
- Azure DevOps
- Azure AI
- Foundry
- SAST
- DAST
- Python
- Azure
1 month ago
Location ; Remote
Long Term Contract
Key Responsibilities
- Provide security guidance and oversight throughout the SDLC.
- Review code scanning results and security findings, partnering with development teams on remediation strategies.
- Evaluate application and solution architectures to identify security risks and recommend controls.
- Collaborate with engineering teams to integrate security into CI/CD pipelines and development processes.
- Promote secure development practices and DevSecOps principles across technology teams.
- Conduct application risk assessments and security reviews for new and existing solutions.
- Develop, maintain, and enforce security policies, standards, and development security requirements.
- Identify and mitigate risks associated with cloud, application, and emerging technology environments.
- Provide security consultation and governance for technology initiatives and strategic projects.
- Assess security controls for AI-enabled applications, bots, and intelligent automation solutions.
- Evaluate risks associated with AI platforms, models, and agent-based technologies.
- Partner with stakeholders to establish governance, security standards, and risk management processes for AI initiatives.
- Serve as a trusted advisor to development, technology, and security teams.
- Drive collaboration across cross-functional stakeholders to ensure security requirements are understood and implemented.
- Communicate security risks, recommendations, and remediation plans to technical and business audiences.
- Azure Cloud
- Azure DevOps
- Azure Data Lake
- Azure AI Foundry
- CI/CD pipelines
- Application Security Testing (SAST/DAST)
- Python (preferred but not required)
- 5+ years of experience in Information Security, Application Security, IT Risk, or DevSecOps.
- Strong understanding of secure software development and SDLC methodologies.
- Experience reviewing vulnerability scans, code scanning tools, and security assessments.
- Knowledge of cloud security principles, preferably within Azure environments.
- Experience conducting architecture reviews and application risk assessments.
- Exposure to AI security concepts, controls, and governance frameworks.
- Strong communication and stakeholder management skills.
- Experience working within regulated environments preferred; financial services experience is a plus.
Senior IT Risk & DevSecOps Analyst · Perfict Global, Inc.