We are looking for a Senior DevSecOps Engineer to integrate security into our SDLC, CI/CD pipelines, applications, and cloud-native environments. The role will work closely with Development, DevOps, SecOps, and SOC teams to automate security testing, perform security assessments, and improve application security. Key Responsibilities
Design and improve Secure SDLC and DevSecOps processes.
Implement security controls in GitLab CI/CD pipelines.
Implement and manage SAST, DAST, SCA, secret scanning, and container scanning.
Perform penetration testing and security assessments of web applications, APIs, and services.
Validate vulnerabilities, analyze exploitability, eliminate false positives, and provide remediation guidance.
Perform application, API, source-code, and security configuration reviews.
Manage and prioritize vulnerabilities and coordinate remediation with development teams.
Automate security workflows and integrations with Jira, DefectDojo, SIEM/SOAR, and other security platforms.
Implement security controls for Docker, Kubernetes, and IaC environments.
Define security test cases based on OWASP, CWE, and industry best practices.
Support threat modeling and security architecture reviews.
Required Skills
Strong knowledge of DevSecOps, Secure SDLC, Application Security, and Penetration Testing.
Hands-on experience with Web Application and API Penetration Testing.
Strong understanding of OWASP Top 10, OWASP API Security Top 10, CWE, and common attack techniques.
Experience with Burp Suite, Nmap, Nessus, and other penetration-testing/security assessment tools.
Hands-on experience with GitLab CI/CD.
Experience with SAST, DAST, SCA, secret scanning, and container scanning.
Experience with Docker, Kubernetes, Linux, and IaC security.
Experience with tools such as Semgrep, DefectDojo, Trivy, Checkov, or similar.
Automation and scripting skills using Python, Bash, REST APIs, and webhooks.
Strong vulnerability analysis, troubleshooting, communication, and cross-team collaboration skills.
3+ years of relevant cybersecurity, DevOps, AppSec, penetration testing, or software engineering experience.
3+ years of hands-on DevSecOps, Application Security, or penetration-testing experience.