Delta is focused on sustaining a strong IT operation, growing our capabilities, and maximizing optimization across each of our tech hubs to elevate the travel experience for our customers and empower our 90,000 Delta people.
We’re committed to fostering innovation, and we’re excited to invite you to be part of our journey as we shape the future of technology at the world’s best airline!
Do you enjoy solving advanced technical problems, and working with best-in-class security tools? Yearn for the opportunity to build a world class application security testing organization? Enjoy building and supporting successful relationships through direct interaction with peers, managers, and other technical teams? Partnering with management to build a collaborative working environment while promoting high standards, exercising good judgment and professionalism? If you do, then it sounds like you are just the person we are looking for to join our Information Security Team at Delta Air Lines.
The successful candidate will use DevOps practices to support the enterprise in adapting its development and DevSecOps methodologies. This role involves leading the deployment and configuration of modern development tools to help the company’s cloud journey. Additionally, the candidate will apply secure coding best practices to find and address application vulnerabilities. The ideal candidate will have experience in implementing, deploying, and providing support for custom AWS Config Rules, CFN Hooks, and CFN Guard Rules. Be comfortable supporting applications across various cloud platforms, including AWS, Azure, and GCP. Have experience building custom developed automated solutions utilizing cloud resources. A strong background in reviewing open-source components is essential, along with the ability to recommend configuration or environmental changes that enhance security and reduce risk in 3rd Party components used by in-house developed applications. The candidate must be solutions-oriented, employing rigorous logic and methods to effectively tackle complex problems while exploring all available resources for answers. Strong documentation skills and familiarity with the complete software development life cycle are also crucial for success in this role.
Full time remote is not an option.
Key Responsibilities:
- Leads projects to implement tools in CICD pipelines to implement automated Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA).
- Works within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines
- Designs, develops, plans, implements, and supports Cloud DevSecOps processes across multiple business units, ensuring alignment with secure coding best practices.
- Possess extensive knowledge of CI tools such as Jenkins, Tekton, CircleCI, Gitlab, AWS CodePipeline etc.
- Test driven mindset with experience in automation with development tools
- Facilitates training on enterprise tools and best practices
- Collaborate with and across Agile teams to design, develop, test, implement, and support technical solutions in full-stack development tools and technologies
- Apply software development skills (e.g., Java, C.NET, JavaScript) to recommend and apply secure coding practices
- Utilize programming languages like JavaScript, Java, HTML/CSS, TypeScript, SQL, Python, and Go, Open-Source RDBMS and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of AWS tools and services
- Knowledge of OWASP secure coding standards.
- Experience with Agile methodologies.
- Experience with AWS and Kubernetes
- Consult with development Teams to perform security reviews of software designs and help developers to ensure quality and robustness of our internal products
- Conduct security assessments against web applications and APIs across a variety of technology stacks
- Performs technical design reviews and code reviews.
- Drive awareness and knowledge of security in the developer community.
- Provide technical leadership for the application security and cloud security teams