DevOps Engineer II
Trimble
Roles and responsibilities:
Implement security controls for cloud (AWS & Azure) systems
Thoroughly document implementations, via technical documentation and run-books
Configure and manage security and compliance solutions using cloud-native security solutions & services.
Build, deploy, and manage production security tools and services to monitor networks, endpoints, and cloud workloads
Create and execute patch management plans for Windows, Linux, and applications. Identify, test, and deploy security patches promptly to mitigate vulnerabilities and ensure compliance.
Develop and deploy backup strategies using AWS and Azure Backup to ensure data protection, compliance, and integration into the disaster recovery (DR) strategy.
Monitor backup jobs, troubleshoot issues, and optimize performance for AWS and Azure. Review and update backup policies, schedules, and retention settings to ensure data integrity.
Organize and execute disaster recovery drills and tests. Collaborate with IT, business units, and partners to ensure all stakeholders are prepared for swift action during incidents.
Develop and maintain reusable code libraries for patch management automation. Ensure libraries are well-documented and accessible, and promote consistency and efficiency.
Design and implement automated patching strategies for Kubernetes, ECS, EKS, AKS, and Elastic Beanstalk using tools like Kured and AWS CodeDeploy.
Partner closely with security leadership, compliance, engineering, and IT Teams to execute security strategies for our cloud objectives
Assist in responses to external audits and vulnerability assessments for various teams
Document and maintain standard operating procedures (SOP)
Support Cloud security operations including security alerts, incidents, change control and reporting, aligning to SOC activities.
Candidate requirement:
2+ years experience in cloud security, ideally AWS and Azure
Engineering mindset with a relevant cloud and security background & understanding
Should have worked on AWS and Azure (hands-on experience)
Knowledge of serverless architectures and containerization (e.g., AWS Lambda, Amazon ECS/EKS).
Good knowledge in Python, Shell and Powershell or any other scripting languages
Experience with Infrastructure as Code (IaC) tools such as AWS CloudFormation or Terraform.
Familiarity with networking, security, and storage solutions on AWS and Azure.