DevOps ArchitectLocation: Miami, FL Duration: Contract Rate: DOEMust-have skills:DevOps, DevSecOps roles, Cloud Service Providers (AWS)DevOps tools such as Git OR Jenkins OR Ansible OR TerraformInfrastructure as Code (Terraform)Java OR Java Spring Boot OR Python OR C/CSecurity experience: SAS (static analysis), threat modeling, log monitoring, APIs to query RESTful services, micro services, Python, Go, or Bash, Kubernetes, Docker, and Rancher, CI/CD, GitLab, SAST, DAST, IAST, MAST; Linux, HashicorpRequirements:Availability to work at the Client's site in Miami, FL (required)Experience within DevOPs, DevSecOPs roles (5+ years)Experience with Cloud Service Providers (AWS heavily preferred) (5+ years)Experience with container technologies like Kubernetes, Docker, and RancherExperience with Infrastructure as Code (Terraform) (2-3 years)Experience with DevOps tools such as Git, Jenkins, Ansible, and TerraformExperience with DevOps and Agile methodologiesExperience using APIs to query RESTful services and integrate third party services, micro servicesProgramming experience using one or more of the following: Java, Java Spring Boot, Python, or C/C+Experience with CI/CD - Deployment pipelines, and automated build and configuration tools such as GitLab, Jenkins, Ansible, and TerraformSecurity experience: SAS (static analysis), threat modeling, log monitoringExperience with security automation and scripting with languages like Python, Go, or BashExperience with security automation, security log review and analysis, threat analysis toolsExperience with DevSecOps practices, including automation of SAST, DAST, IAST, MAST along with threat modeling, code peer reviews, security remediation and security monitoring/incident response enablementExperience in Linux operating systemsExperience with cloud security controls involving tenant isolation, encryption at rest, encryption in transit, and secrets management (Hashicorp preferred)Ability to travel both locally and internationally 25% of the timeResponsibilities:Design, implement and maintain secure, reusable DevOps pipelines for brand development teams, that align with Carnival global application security standardsDevelop and maintain infrastructure as code (IaC) templates for cloud environments such as AWS, Azure, and Google Cloud PlatformWork with development teams to ensure that security is built into the SDLC and that all code is secure by designMonitor and investigate security incidents and vulnerabilities in the infrastructure and take corrective actionsContinuously assess and improve the security posture of the brand and contribute improvements back to the global organizationProgram, engineer, implement, and administer IT Security technical control and tools to assess vulnerabilities, mis-configurations and incidentsDevelop and maintain relationships with 3rd party vendors responsible for providing technology services, tools, and consultingPerform security reviews of deployments to ensure they meet relevant policies, standards, and guidelinesPartner with different brand IT resources to automate and enhance security logging and integrate with managed SIEM providerCreate and distribute security reports to required business and IT units, including vulnerability reports for tracking of remediationRespond to escalations and other priorities as required, may require afterhours engagement as neededOther projects and duties as assigned (e.g., assisting global application security pillar on pattern and capability design and buildout)