- You will build, maintain, and continuously improve an automatedsecurity pipeline frameworkintegrated into our CI/CD environments.
- You will lead development ofInfrastructure-as-CodeandPolicy-as-Codefor application security enforcement and consistency across environments.
- You will evaluate and integrate security tools (SAST, DAST, SCA, CSPM, EDR) andAI-based solutionsinto engineering workflows and CI/CD pipelines.
- You will provide applicable guidance and mentorship to development and Avalara Security engineering teams on secure development best practices.
- Investigate, prototype, and applyAI/ML-based solutionsfor application behavior analysis, anomaly detection, and threat hunting.
- Promote security by design across the organization, and help foster a security-first culture.
- Contribute to the continuous refinement of the SDLC to ensure security is smooth, consistent, and measurable.
What Youll Need to be Successful
Required Qualifications
- 8+ years of experience inapplication security, secure software development, or security engineering.
- Strong programming proficiency inPythonandGoLang(hands-on).
- Experience with secure SDLC practices and CI/CD pipeline integration.
- Strong hands-on experience withKubernetes, container security, andcloud infrastructure securitypreferablyAWS and GCP.
- Experience withInfrastructure-as-Code (IaC)tools like Terraform or CloudFormation.
- Working knowledge of cryptographic protocols and standards:TLS, OAuth, SAML, JWT, etc.
- Familiarity withGit, modern source control practices, and agile development methodologies.
- Experience working with a broad range ofsecurity tools, including:
- Tenable,Wiz(Cloud Security Posture Management)
- Checkmarx,Mend(SAST, SCA)
- Acunetix,Burp Suite(DAST)
- CrowdStrike(EDR/XDR)
- Bachelors Degree in Computer Science, Engineering, or a related field.
- Proven experience contributing tosecurity automation efforts within a security organization like Avalara Security.
- Experience withAI/ML tools and frameworksapplied to application security or behavior analytics.
- Security certifications such as OSWE, CSSLP, AWS Security Specialty, or Kubernetes Security Specialist.
- Passion for enabling developer-friendly security solutions and maximum automation.