Essential Services : Role & Location fungibility
In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team. To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service. The role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature.
About the role
As a DevSecOps Manager, you will be responsible for implementation of security tools in DevOps CI/CD (Continuous Integration/ Continuous Delivery) pipeline and publish security standards and best practices for developer team.
You will be responsible for integrating, monitoring and improving cloud security controls via DevSecOps processes. In this role, you will perform assessments and help to mitigate security finding and implement improvement security measures. You will keep abreast of new technologies like Docker, Kubernetes, etc., to ensure that the organization remains at the forefront of security. Experience in analysing threats of cloud and familiarity with OWASP, SANS vulnerabilities along with its validations in source code and other security frameworks is an advantage.
Key Responsibilities
Identifying Vulnerabilities
Enable automated security scanning process to identify the known vulnerabilities in source code, Open-source library, and configuration. Provide technical leadership and direction in the DevSecOps domain.
Analysis
Troubleshoot DevSecOps pipeline implementation issue and support for successful deployment. Implement DevSecOps with multiple agile teams across various platforms, environments, and instances. Implement Automated DevSecOps template-based solutions for cloud environments.
Implement Security Measures
Understand the Security Requirements & Implement the new DevSecOps process. Configure Cloud Security Tools/Systems in a CI/CD Pipelines. Implementing Security scanning into Jenkins, Code Pipeline, and DevOps workflows. Define gating process metrics for security and implement in DevSecOps. Employ infrastructure as code to increase automation, scalability, and reliability.
Reporting
Prepare and provide necessary metrics, detailed reports, artifacts, executive summary and dashboard to leadership on a regular frequency. Build and maintain a set of tools that enable developers to self-serve for remediation. Monthly Dashboard Reporting for Leadership.
Collaborate
Capable of working in a dynamic environment, multi-department coordination and attaining the target.
Qualifications & Skills
Educational Qualification
Engineering Graduate in CS, IT, EC or InfoSec, CyberSec or MCA equivalent with certification of CSSLP, CISSP, GPEN, ECSA, CEH, CISM, CISA, or equivalent will be an added advantage
Compliance
Good understanding of cyber security trends & hacking techniques. Experience in analysing threats of cloud and application components. Ability to review assessment reports to provide risk mitigation & recommendations on that basis.
Technical Skills
Experience with various application security tools including SAST, DAST, Software composition analysis and application Penetration testing. Experience with Automation in testing or orchestration Selenium, Maven, Ant, Msbuild, Npm, Yarn, Jenkins, Gitlab, Bitbucket, etc. Knowledge of Agile and Scrum processes.
Communication Skills
Outstanding communication abilities. Ability to effectively communicate the required recommendations.

Keyskills: kubernetes docker devops jenkins dast technical leadership owasp bitbucket security framework risk mitigation selenium ecs code pipeline sast cisa san maven ant msbuild npm application penetration testing scrum gitlab devsecops agile yarn