Security Operations Engineer at Opal Labs
Portland, OR, US
About Opal

At Opal, we believe enterprise software should be beautiful, simple and designed for the job at hand. Opal is a collaboration platform, built for brand marketing teams to produce, organize and govern creative content.

The Opal StoryFirst™ framework empowers teams with a dedicated environment to visualize and deploy campaigns across all marketing channels, reducing complexity and aligning teams for better marketing results. Our customers are creative, passionate people and, through a platform tailored to their specific needs, we’re helping them rediscover the best parts of their jobs.

Our team is deeply invested in creating a culture that promotes design thinking, collaboration and a passion for excellence. We are building a world class lineup of creative and strategic thinkers that work together as a team to revolutionize the modern marketing organization.

The Position

We are seeking a DevSecOps / SecOps Engineer who knows that delivering amazing user experiences, maintaining developer happiness, and ensuring rock-solid security are mutually inclusive goals. The ideal candidate is excited to work on a robust suite of web and mobile applications, allowing creative teams to collaborate and thrive in fast-paced environments at Fortune 500 brands and agencies all over the world. As a Security Operations Engineer at Opal, you will constantly improve the robustness of our security practices, tools and infrastructure, helping our engineering teams maintain the sky-high level of trust our organization has built with customers across the globe.

Responsibilities

Software Engineering + Security
Perform Static code analysis on source code and manage remediation.
Ensure the secure architecture, design, development, coding and configuration of both existing systems as well as new initiatives.
Coach fellow engineers on best practices for maintaining security throughout the software development lifecycle.
Security Ops
Engineer security into continuous integration systems.
Implement, maintain, and improve security infrastructure.
Develop technical solutions and select or build new security tools to mitigate vulnerabilities.
​Security Documentation & Communication
Act as point (for the Product team) for all activities supporting key security certifications and the associated audits (i.e. ISO 27001, SOC 2, etc.).
Create requirements and documentation for security systems.
Communicate to senior management regarding threats, risks, and issues.
Effectively communicate security remediation strategies.
DevOps
Support infrastructure, systems, and services for the Opal platform.
Build scalable tools, systems, and processes that allow your fellow engineers to ship world-class software and that support Opal’s security posture and compliance.
Skills

3-5+ Years of DevOps / SecOps / DevSecOps experience supporting enterprise-grade web applications
Experience managing internal privacy and security certifications such ISO 27001 and SOC 2
Proven ability to act as an internal champion for security within engineering teams
Static code analysis experience across a broad swatch of languages
Demonstrated ability to engineer security into full stack architectures on next-generation cloud and container platforms
Deep knowledge of one or more server configuration management frameworks such as Chef, Puppet, Ansible, or SaltStack
Detailed understanding of security industry standards and frameworks from OWASP, CIS and NIST
Proven ability to manage projects, gaining consensus and buy-in cross functionally
Proven ability to drive initiatives with diplomacy and empathy
Nice to Haves

Certifications like: AWS Certified Solutions Architect, AWS Certified Security, CISSP, CCSK/CCSP, CISSP-ISSEP/ISSAP, CSSLP, SABSA SCF/SCP/SCM
Familiarity with Ruby, Rails, Elixir, and NodeJS
Familiarity with the Heroku PaaS ecosystem
Benefits

A full-time, salaried position
Full healthcare coverage (health, dental, vision, FSA)
Short-term disability insurance
Early-stage stock options
Company-sponsored retirement program
Company-sponsored outreach & activity programs
A tight-knit, very supportive team — we pride ourselves on our culture
A fun, open office with ping pong, video games and snacks for days
Exposure to some of the biggest brands on the planet
At Opal, we are building a world class organization of creative and strategic thinkers. There are no individual egos at Opal, only a team that strives to revolutionize the modern marketing organization.