Want to know if you’re a fit? Upload your resume and let our AI show you.
Skills
Artificial Intelligence (AI)unmatched
Automationunmatched
Bash Scriptingunmatched
Best Practicesunmatched
Business Solutionsunmatched
Cloud Computingunmatched
Computer Scienceunmatched
Configuration Managementunmatched
Continuous Deployment/Deliveryunmatched
Continuous Improvementunmatched
Continuous Integrationunmatched
Cross-Functionalunmatched
DevOpsunmatched
Establish Prioritiesunmatched
Go Programming Language (Golang)unmatched
Hybrid Cloudunmatched
Incident Responseunmatched
Information/Data Security (InfoSec)unmatched
Infrastructure Softwareunmatched
Javaunmatched
Leadershipunmatched
Machine Learningunmatched
Machine Toolunmatched
Maintain Complianceunmatched
Microservicesunmatched
Multiplatform/Cross-Platformunmatched
Performance Metricsunmatched
Process Improvementunmatched
Product Engineeringunmatched
Protective Servicesunmatched
Python Programming/Scripting Languageunmatched
Regulationsunmatched
Regulatory Requirementsunmatched
Requirements Managementunmatched
Risk Managementunmatched
Scripting (Scripting Languages)unmatched
Security Infrastructureunmatched
Security Monitoringunmatched
Supply Chainunmatched
Team Lead/Managerunmatched
Test Automationunmatched
Description
About the Role
In this role, you will lead the strategy design and delivery of security engineering solutions that protect the companys assets, infrastructure, and software supply chain. You will manage a team of security and DevOps engineers driving a culture of security-first delivery across Cloud Security, CICD Pipeline Security, Product Security, and Infrastructure Security. You will partner closely with Engineering, Product, and Leadership to set direction and ensure the business ships software with speed and confidence.
What Youll Do
Lead the design, development, and implementation of information security solutions across Cloud Security, Infrastructure Security & Product Security.
Own the security strategy for CICD pipelines, including automated testing, SAST/DAST scanning, dependency checks, and secrets detection - providing technical advisory and governance across hybrid multi-cloud environments.
Drive cloud security posture management, runtime protection, and code security through industry-leading cloud security and edge protection capabilities, ensuring continuous compliance and risk reduction.
Define and enforce security policies, standards, and best practices that balance delivery speed with a strong security posture in alignment with regulatory and legal requirements.
Lead automation initiatives across cloud security processes, reducing manual effort and improving consistency at scale.
Oversee API security standards and runtime protection across services and microservices architectures.
Manage infrastructure security controls using infrastructure-as-code and container orchestration tooling in line with container security best practices.
Anticipate operational and program risks, developing preventative measures and driving rapid incident response across environments.
Translate functional security requirements into technical roadmaps, guiding your team from strategy through to execution.
Define, track, and communicate security metrics and key performance indicators - creating actionable insights from data to inform prioritization, demonstrate delivery effectiveness, and drive continuous improvement.
Build strong cross-functional relationships with product and engineering squads, embedding security into development workflows and acting as a trusted security advisor at the leadership level.
Who You Are
A proven leader with hands-on depth in DevSecOps or security engineering and the ability to inspire, grow, and manage a high-performing team.
Demonstrate deep knowledge of infrastructure security practices, concepts, and technologies with proficiency across cloud security capabilities and modern security methodologies.
Experience governing CICD pipelines and authoring configuration management and deployment tooling across modern CICD platforms.
Strong scripting and development skills across languages such as Python, Bash, Go, or Java.
Solid understanding of cloud security concepts, including network segmentation and secrets management across major cloud providers.
Experience anticipating operational risks and driving preventative measures across complex, fast-moving engineering environments.
A confident communicator who can translate security priorities to developers, stakeholders, and executives alike.
Familiarity with AI and machine learning capabilities as applied to DevSecOps and infrastructure management - including AI-assisted threat detection, anomaly detection, intelligent vulnerability triage, and the use of AI-powered tooling to enhance security automation and operational insight - is considered a strong advantage.
Background in Computer Science, Information Security, or equivalent practical experience.
Numbers & Facts
Location
San Francisco, CA
Industry
All
Company Size
10,000 employees or more
Website
http://www.gap.com
About Company
Doris and Don Fisher opened the first Gap store in 1969 with a simple idea -- to make it easier to find a pair of jeans and a commitment to do more. Over the last 46 years, the company has grown from a single store to a global fashion business with five brands -- Gap, Banana Republic, Old Navy, Athleta and Intermix. Gap's clothes are available in 90 countries worldwide through 3,300 company-operated stores, almost 400 franchise stores, and e-commerce sites and is still growing.
Many companies work to improve their services and businesses every day by using GAP Testers who anonymously go into various places and report back to the companies on everything from cleanliness, customer service to quality control. Being a tester is a very flexible, fun job with lots of benefits.