IT Security Implementation - Hardening & DevSecOps

2,000
ETH, DAI, USDT
+53
27 days (till Dec 31st, 2025)

Overview

Harden development workflows, standardize secrets management, complete endpoint/MDM coverage, and operationalize incident readiness.

Objectives

Enforce org-wide repository protections and hygiene (GitHub/GitLab).

Consolidate secrets into an approved manager; move CI/CD to short-lived, federated access (OIDC).

Reach 100% Windows/macOS enrollment with EDR/MDM and escrowed disk encryption; gate unmanaged devices.

Validate SIEM alert routing; finalize comms/escalation; prep Month-3 tabletop.

Scope

Code & Dev: Branch protection, required reviews/checks, secret scanning/push protection, runner isolation, dependency security, CODEOWNERS.

Secrets & CI/CD: Vault integration, env-scoped secrets, token hygiene/rotation, OIDC to cloud roles.

Endpoints & MDM: Windows 10 & macOS 15 enrollment, FileVault/BitLocker escrow verification, conditional access to block unmanaged/BYOD.

Monitoring & IR: On-call alert routing, concise comms/escalation runbooks, tabletop prep (executes in Part 3).

Methods

Change-controlled rollouts with backout plans.

Short stakeholder sessions for approvals/exceptions.

Read-only validation where practical; evidence collection (exports/screenshots).

Mapping to ISO 27001, NIST CSF, CIS Controls.

Key Responsibilities

DevSecOps Controls: Apply org-wide branch protection & required checks; enable secret scanning/push protection; remove plaintext secrets; isolate runners; turn on dependency security updates.

Secrets Standardization: Migrate CI variables to the approved vault; adopt OIDC for pipeline cloud access; define token lifetimes/scopes and rotation norms.

Endpoint & MDM: Achieve 100% EDR/MDM enrollment on Windows/macOS; verify FileVault/BitLocker escrow; block unmanaged/BYOD from sensitive apps via conditional access.

IR Operationalization: Validate SIEM alert routing to on-call; finalize comms/escalation runbooks; prepare the Month-3 tabletop brief.

Deliverables

Repository Governance Pack: Enforced branch protections, required checks, exceptions register; elevated-role review results.

Secrets Hygiene Closure: Org-wide secret scanning enabled; remediation log; CI/CD on vault-backed secrets and OIDC; token policy (max age/permissions).

Endpoint Compliance Set: 100% EDR/MDM enrollment; disk-encryption escrow evidence; conditional-access gating for unmanaged devices; time-bound exceptions.

IR Operational Readiness: Alert-routing tests with acknowledgment workflow; finalized comms/escalation runbooks; tabletop packet ready for Part 3.

Qualifications

GitHub/GitLab org governance (branch protection, checks, secret scanning rollout/remediation).

Enterprise secrets manager integration; CI/CD OIDC federation; retirement of long-lived keys.

Windows/macOS fleet hardening (EDR/MDM enrollment, encryption escrow, conditional access).

SIEM alert routing/testing; incident comms runbooks; strong documentation and change control.

Nice-to-have: ISO 27001/CIS/NIST CSF experience; CISA/CISM/CISSP.

2,000
ETH, DAI, USDT
+53
27 days (till Dec 31st, 2025)

More Jobs like this

Show more
ترجمه ویدیو و تایپی

English French German translation from video to type 

copy and paste.

I’m currently looking for talented copywriters — beginners, mid-level, or experienced — to join upcoming projects.   Available Roles:   Website Copywriter Sales & Marketing Copywriter Social Media Copywriter Content Writer / Article Writer General...

Need Asia developer(Not India, Pakistan, Bangladesh)

I am looking for developer who lives in Asia, not India, Pakistan, Bangladesh. The man who can help me to pass ID or Passport verification. Also this will be long term collaboration. Hope to connect...

Crypto Market Analyst & Trader

I am an active trader and market analyst specializing in cryptocurrency, price behavior, macro trends, and risk management. Alongside hands-on trading experience, I work with data, market structure, and trader psychology, ensuring every output is...

Web site

1. What the site should offer (for customers):Homepage: Banner, block for popular/new items. Navigation to categories (e.g., "T-Shirts", "Shorts").Product Catalog: List of products (photo, name, price). Clicking a product leads to its dedicated page.Product Page:...

Chief Financial Officer (CFO)

We’re looking for a strategic Chief Financial Officer (CFO) to design financial architecture and lead fundraising across private and public rounds. This role goes far beyond bookkeeping — you’ll be a strategic partner to the...

Таргетолог

Ищем таргетолога Facebook / Instagram для запуска рекламы лид-формЧто нужно сделать:— корректно подключить заявки к AMО CRM;— обеспечить стабильную работу рекламных кабинетов (опыт обхода блокировок обязателен, мы находимся в РФ);— показать примеры кампаний по Казахстану,...

Hiring Professional Video Editor (Project-Based, Remote)

  We are looking for a creative, skilled video editor proficient with AI tools to deliver high-quality results on professional projects. Type of collaboration: Project-based | Fully remote | Competitive pay | Potential for long-term...

Programamer

I would like to find work as a back end developer 

Twilio API Bot

"I need the back end for my CRM made so I can perform mass sms campaigns to people that respond to my Instagram and Facebook ads" I've been having an issue where my twilio stops...

ترجمه ویدیو و تایپی

English French German translation from video to type 

copy and paste.

I’m currently looking for talented copywriters — beginners, mid-level, or experienced — to join upcoming projects.   Available Roles:   Website Copywriter Sales & Marketing Copywriter Social Media Copywriter Content Writer / Article Writer General...

Need Asia developer(Not India, Pakistan, Bangladesh)

I am looking for developer who lives in Asia, not India, Pakistan, Bangladesh. The man who can help me to pass ID or Passport verification. Also this will be long term collaboration. Hope to connect...

Crypto Market Analyst & Trader

I am an active trader and market analyst specializing in cryptocurrency, price behavior, macro trends, and risk management. Alongside hands-on trading experience, I work with data, market structure, and trader psychology, ensuring every output is...

Web site

1. What the site should offer (for customers):Homepage: Banner, block for popular/new items. Navigation to categories (e.g., "T-Shirts", "Shorts").Product Catalog: List of products (photo, name, price). Clicking a product leads to its dedicated page.Product Page:...

Chief Financial Officer (CFO)

We’re looking for a strategic Chief Financial Officer (CFO) to design financial architecture and lead fundraising across private and public rounds. This role goes far beyond bookkeeping — you’ll be a strategic partner to the...

Таргетолог

Ищем таргетолога Facebook / Instagram для запуска рекламы лид-формЧто нужно сделать:— корректно подключить заявки к AMО CRM;— обеспечить стабильную работу рекламных кабинетов (опыт обхода блокировок обязателен, мы находимся в РФ);— показать примеры кампаний по Казахстану,...

Hiring Professional Video Editor (Project-Based, Remote)

  We are looking for a creative, skilled video editor proficient with AI tools to deliver high-quality results on professional projects. Type of collaboration: Project-based | Fully remote | Competitive pay | Potential for long-term...

Programamer

I would like to find work as a back end developer 

Twilio API Bot

"I need the back end for my CRM made so I can perform mass sms campaigns to people that respond to my Instagram and Facebook ads" I've been having an issue where my twilio stops...