Fractional DevSecOps / Application Security Engineer - B2B Software
Buget: -
HOURLY / PART_TIME
⭐ 0.00 (0)
Canada
application-security, cloud-security, owasp
Calificări preferate
- Experiență: Expert
- Job Success: 90%+
- Rising Talent preferat
- Câștig min.: $10,000+
We are looking for an experienced application-security and DevSecOps engineer to review and help secure an existing B2B software application being prepared for external pilot use.
This is initially a fractional engagement.
The successful candidate should be comfortable reviewing real application code and cloud architecture and helping implement remediation rather than only producing an assessment report.
Scope
Potential areas of work include:
- Application threat modeling
-Authentication and authorization review
- Customer/workspace data isolation
- Cloud IAM and least privilege
- Encryption in transit and at rest
- Secrets management
- Secure file/document handling
- API security
- Third-party API data flows
- Logging and sensitive-data exposure
- Dependency and vulnerability management
- Docker/container security
- CI/CD security
- SAST and secrets scanning
- Backup and recovery controls
- Security monitoring
- Data retention and deletion controls
- Incident-response readiness
- Required Experience
Strong hands-on experience with:
- Application security
- DevSecOps
- AWS and/or Azure security
- IAM
- Web and API security
- Docker
- CI/CD security
- Secrets management
- Vulnerability management
- OWASP practices
- Threat modeling
- Secure software-development practices
Python/FastAPI experience is strongly preferred.
Experience securing B2B applications that process confidential customer information is highly desirable.
Initial Engagement
The initial engagement would likely involve:
1. Reviewing the proposed -production architecture.
2. Reviewing application data flows and trust boundaries.
3. Producing a practical threat model.
4. Identifying critical issues that should be addressed before pilot deployment.
5. Helping implement or verify priority remediation.
6. Producing a concise pre-release security checklist.
We are looking for practical security engineering appropriate to an early-stage application, not unnecessary compliance bureaucracy.
Additional business and technical information will only be disclosed to shortlisted candidates and may require a confidentiality agreement.
Please Answer
- Describe a B2B application where you personally performed application-security or DevSecOps work.
- What are the biggest security risks when an internal application is moved to an externally accessible cloud environment?
- What AWS or Azure security services have you implemented directly?
- Describe your experience with SAST, dependency scanning, secrets scanning, container security, and CI/CD security.
- Are you comfortable reviewing and helping implement remediation rather than only producing an audit report?
Deschide pe Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Autentificare