$ cat jobs/senior-cybersecurity-specialist-devsecops-vulnerability-mana-airnewzealand-d57d387bcd2b.json
Senior Cybersecurity Specialist (DevSecOps/ Vulnerability Management/ Cloud/ WAF)
Kia ora! Help protect one of New Zealand’s most recognised brands. As a Senior Cybersecurity Specialist, you'll strengthen our security capability by improving cloud security, embedding DevSecOps practices, and reducing cyber risk across the business. Air New Zealand is on an accelerated journey to become the world's leading digital airline. You'll join a collaborative Cyber Security team that works across our Digital function to build secure, resilient technology that supports millions of customer journeys. About the role Identify security vulnerabilities and risks, and support remediation planning and prioritisation. Support and enhance SDLC security tooling (for example, SAST and SCA) to enable DevSecOps practices. Implement and improve cloud security controls. Monitor, review and maintain WAF rules and performance. Monitor compliance with security controls for outsourced infrastructure providers. Analyse security metrics and produce security health reports to support decision-making. Monitor security incidents and events using security tools, and coordinate resolution with internal and external teams. Participate in security incident response and resolution activities. Maintain and publish security policies, standards, processes and guidelines. Provide security analysis, reporting and insights through research, security metrics, SIEM alerts and incident data. What we're looking for 4+ years' experience in cybersecurity, with expertise in vulnerability management and threat, risk and security analysis. Experience with DevSecOps practices and security tooling, including SAST, SCA and secure SDLC processes. Strong knowledge of cloud security engineering, cloud technologies and hybrid (cloud and on-premise) network environments. Experience managing and monitoring WAFs, including DDoS protection, and security monitoring platforms such as SIEM. Strong understanding of security incident response, security governance and security control frameworks. Sound knowledge of c