SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Showpad is seeking a Senior SecOps Engineer to lead security operations and enhance the organization's cybersecurity posture. This role sits within the Security Operations team and collaborates across Engineering, Product, and business units to identify, manage, and mitigate cybersecurity risks in cloud-native environments.
Key responsibilities include managing cybersecurity operations across application, hardware, and cloud infrastructure; serving as the primary security contact for internal teams on daily practices and company-wide initiatives; ensuring development teams adopt secure software development best practices; enabling teams through CI/CD processes that integrate security tooling; managing and improving the CNAPP solution; overseeing continuous monitoring and protection of cloud infrastructure; managing and responding to vulnerability programs, endpoint protection, user behavior analytics, firewalls, IDS/IPS, and external threat intelligence; collaborating on security policy adherence; developing security controls and automation strategies within CI/CD pipelines; and monitoring, assessing, and mitigating risks and vulnerabilities.
The ideal candidate brings solid SecOps experience and deep understanding of modern security methodologies. This is an individual contributor role focused on technical security operations and enablement rather than people management.
REQUIREMENTS:
- Proven experience in information security with background in security operations, application security, or related roles
- Skilled in identifying, analyzing, and handling phishing attempts and social engineering threats
- Strong knowledge of modern web application security practices and frameworks
- In-depth understanding of Secure Software Development Life Cycle (SSDLC)
- Experience implementing security automation for testing, monitoring, or orchestration workflows in Typescript or similar languages
- Proficiency in container technologies (Docker, Kubernetes) and serverless environments (AWS Lambda) with hands-on experience securing cloud-based applications, preferably AWS
- Knowledge of securing microservices-based architectures
- Practical experience conducting security assessments including SAST, DAST, and SCA
- Experience managing vulnerabilities through bug bounty programs, penetration testing, and automated security scanning
- Understanding of security and privacy frameworks such as GDPR, ISO 27001, and SOC 2 (asset)
- Strong English communication and presentation abilities with capacity to explain complex security concepts to technical and non-technical audiences