What’s on this page

Job Description Our Values Hiring Process

About this job

Description

The Senior DevOps Engineer Enables the automation of software code deployment by eliminating functional silos existing between development and production. The Senior DevOps Engineer work assignments involve moderately complex to complex issues where the analysis of situations or data requires an in-depth evaluation of variable factors.

Responsibilities

In this role you will be on a team of security engineers performing triage, analysis, hunting bugs, driving DevSecOps adoption, delivering on our “everything is code” approach to product development.  Your focus will be shift left DevSecOps opportunities, CI/CD Pipeline scanning, enablement and engineering automation.
 

We are looking for someone with at least 3 years of application security and or offensive security experience

You are a great fit if the following are true:

  • You can handle complicated bugs and complex application security issues.
  • You love developers, teaching, learning, and research.
  • You have a home lab and constantly learning.
  • You are passionate about customer experience.
  • You love breaking and building, can code and hack.
  • Know the OWASP top 10 and understand defensive coding techniques. 
  • Have experience with Git, Gitflow, SAST, DAST, SCA, IAST tooling.
  • Architects and Red Teamers don’t scare you.
  • You love open source, community and collaboration.
  • Have deep experience breaking web applications, APIs, mobile apps and anything that compiles.
  • Can distill complicated issues and communicate to senior leaders the why it’s important and how it works.
  • You have a strong scripting and automation background (you can write in one or more of the following python, JavaScript/TypeScript or PowerShell) Python preferred.
  • Azure Devops or Github automation, or similar experience with CI/CD tooling.
  • Proficiency with managing supporting & deploying Checkmarx, AppScan, Veracode, Rapid7, Fortify or similar tools.

Responsibilities:

• Partner with our Security Advocate Community, Compliance and governance, platform teams, DevSecOps and DevOps teams.

• Improve and expand application security quality across our entire portfolio of applications.

• Mentor others, you love to share and support, serve as expert for escalated analysis.

• Contributes to inner source and demonstrates engineering community engagement.

• Review and research issues from our Threat Modeling program, tying potential threats to visible defects from security scans

• Help developers solve application security defects.

• Contribute to and execute on our secure software development strategy for the enterprise.

• Improve and expand application security quality across our entire portfolio of applications.

Required:

• At least 3 years+ of experience with Application Security, including familiarity with the leading toolsets supporting Application Security (dynamic and static). Experience with Checkmarx, AppScan, Burp Suite, Contrast, VeraCode, NowSecure, Blackduck, WhiteSource, Fortify or similar tooling.

• Strong application security experience across a variety of technologies and languages.

• Deep experience in static code analysis and third-party software composition analysis.

• Deep experience with BurpSuite and breaking web applications.

• Excellent communication skills with the ability to influence others

• Analytical and problem solving skills

• Strong scripting skills, can quickly find common issues across large code bases or IP ranges. 

• Contributes to the broader security or open source community.  

• Must be passionate about contributing to an organization focused on continuously improving consumer experiences

• Must be passionate about developer experience, privacy, security, quality and product delivery

• Can demonstrate exploitation and break applications with ease, is creative and thinks evil by default.   

Preferred:

• Prior experience leading an application security program, with 1000+ stakeholders and development teams in the portfolio

• Prior experience managing, supporting and deploying SAST/DAST and Open Source Analysis programs and tools across an organization

• Cloud experience or experience with Docker or similar container platforms.

• Working knowledge of Linux and Windows operating systems

• Reverse engineering, bug hunting, vulnerability assessment, or exploit development experience.

• Strong Experience with one of the following: C#, JavaScript, Java, Python, ruby or similar. 

• You understand design, delivery, and ownership along with modern SDLC practices.

• Knowledge of common information security management frameworks, including but not limited to:

ISO 27001/27002, ITIL, COBIT, NIST, BSIMM.

• Professional security certification, such as OSCP, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials a plus but not required.

• Experience with Service Now Asset Management is a plus

               

Scheduled Weekly Hours

40

Equal Opportunity Employer
It is our policy to recruit, hire, train, and promote people without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, or veteran status, except where age, sex, or physical status is a bona fide occupational qualification. View the EEO is the Law poster.

If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact yourcareer@humana.com for assistance.

Humana Safety and Security
Humana will never ask, nor require a candidate to provide money for work equipment and network access during the application process. If you become aware of any instances where you as a candidate are asked to provide information and do not believe it is a legitimate request from Humana or affiliate, please contact yourcareer@humana.com to validate the request.

California Residents
If you are a California resident and would like to review our California Consumer Privacy Act (CCPA) Policy click here:
CA Resident Privacy Policy

Our Values

At Humana, passion fuels our power, our purpose, and our people. We are a diverse team who thinks big and are dedicated to improving the health and well-being of our members, associates, communities, and planet.

Inspire health

Inspire health

Cultivate uniqueness

Cultivate uniqueness

Rethink routine

Rethink routine

Pioneer simplicity

Pioneer simplicity

Thrive together

Thrive together

Upcoming Tech Events

Group of people checking something on IPAD

Hiring Events 3

June 28, 2020 @ 8:00 am - 5:00 pm

Louisville, KY

Group of people checking something on IPAD

Hiring Tech 5

August 25, 2020 @ 8:00 am - 5:00 pm

Louisville, KY

Group of people checking something on IPAD

Hiring Tech 2

August 25, 2020 @ 8:00 am - 5:00 pm

Louisville, KY

View all events

Our Hiring Process

Apply online
To be considered for a job, you must apply online. Unfortunately, we cannot accept resumes that have been emailed to us. Once you find a job that interests you, simply select “Apply.” It typically takes 15 minutes to fill out the application form. Be sure to update your resume and upload it as you cannot edit the resume or add it after the application has been submitted. Shortly after you submit your application, you will receive a confirmation.

Next Step
If selected to continue with the interview process, you will be contacted through text or email to complete an assessment or schedule an initial live or recorded phone or video interview.

A hiring manager interview
After hiring managers and interview teams carefully consider the skills and experiences of applicants, they contact the top candidates via email or phone to schedule an interview.

Offer from Humana
If you’ve successfully completed the interview process and are identified as the candidate we would like to hire, you will receive an offer from our Talent Acquisition team.

Onboarding
If you accept the offer to join our Humana team, you will receive a welcome call or email to begin the onboarding process.

A man welcoming two visitors to the Studio H office. Close-up of green exercise ball. Blue diamond pattern. A professional man and woman working together at a computer.A man welcoming two visitors to the Studio H office. Close-up of green exercise ball. Blue diamond pattern. A professional man and woman working together at a computer.