The shift toward the consumption of IT as a service, i.e., the cloud, is one of the most important changes to happen to our industry in decades. At IBM, we are driven to shift our technology to an as-a-service model and to help our clients transform themselves to take full advantage of the cloud. With industry leadership in analytics, security, commerce and cognitive computing and with unmatched hardware and software design and industrial research capabilities, no other company is as well positioned to address the full opportunity of cloud computing.
We're looking for experienced cloud devops compliance engineers to join IBM Cloud and work on ensuring our company-wide infrastructure's availability, reliability, security, and compliance. This role involves a mix of development, operational duties, strategic planning, and end-user support. You will be part of a strong, agile team that boasts of deep technical expertise, has a significant business impact, and enjoys a high level of operational flexibility. We are running IBM's next generation cloud platform to deliver performance and predictability for our customers' most demanding workloads, at global scale and with leadership efficiency, resiliency and security. It is an exciting time, and as a team we are driven by this incredible opportunity to thrill our clients.
• As a DevOps compliance engineer ensures that software development and deployment processes adhere to relevant regulations and standards, focusing on security, data privacy, and industry best practices, while also collaborating with development and operations teams
- Ensure adherence to industry regulations and data privacy requirements
- Automated Compliance Checks: Integrate automated compliance checks into CI/CD pipelines.
- Validate that systems adhere to security best practices related to encryption, authentication, and secrets management.
- Investigate security breaches or other incidents and refine procedures accordingly.
- Compliance Monitoring: Implement and maintain monitoring systems to track compliance metrics and identify potential issues.
- Stay abreast of the latest technologies and methodologies with high focus on Cloud infrastructure (VPC, Kubernetes/OpenShift, Istio, Akamai etc)
- Minimum 2+ years of experience in Cloud environment in the role of DevOps and compliance monitoring
- Familiarity with continuous integration & continuous deployment tools
- Experience with Infrastructure as Code (Terraform, Ansible).
- Proficient in any one of the high-level programming language such as Python, JavaScript, Java, or Go.
- Proficient in Bash or PowerShell scripting
- Demonstrated experience working with Cloud infrastructure (VPC, Kubernetes/OpenShift, Istio, Akamai).
- Knowledge of various compliance frameworks (e.g., GDPR, HIPAA, PCI DSS, SOC 2) and relevant regulations.
- Ability to perform compliance audits and identify potential risks.
- Excellent analytical and problem-solving abilities, with a keen attention to detail.
- Demonstrated verbal and written communications skills.
- Demonstrated skills with troubleshooting, debugging, maintaining and improving existing software.
- Experience working with any version control system (Git preferred).
- Skill in documenting compliance procedures and policies
- Knowledge of IBM Cloud services and management
- Experience using cloud-native systems for monitoring and alerting (e.g. Prometheus, Grafana, Elasticsearch)
- Exposure to Linux internals
- Understanding of endpoint security best practices (TLS, HTTPS, TLS Certificates, WAF, Network Traffic Analysis)
- Understanding of networking principles and protocols
- Knowledge of security testing techniques to identify vulnerabilities in software and infrastructure.
- Ability to quickly learn new technologies and adapt to changing technical environments