DevSecOps Engineer (SAST/DAST)
NewBe an early applicantSummary
DevSecOps Engineer (3–8 yrs) at Alignity Solutions, an IT consulting firm placing candidates on a long-term client project in Hyderabad (hybrid, contract-to-hire). Day to day: integrating SAST/DAST and penetration testing into CI/CD pipelines with tools like SonarQube, Checkmarx, Veracode, Burp Suite, and Jenkins/GitLab CI, then remediating findings with dev teams.
- Jobseeker Video Testimonials
- Employee Glassdoor Reviews
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Experience:3-8 Years
Requirements
We are looking for an experienced DevSecOps Engineer with strong expertise in SAST, DAST, and Penetration Testing to strengthen application security across the software development lifecycle. The ideal candidate will have hands-on experience integrating security testing into CI/CD pipelines, identifying application vulnerabilities, and working closely with development and DevOps teams to remediate security findings.
The candidate should have a strong understanding of application security, DevSecOps practices, vulnerability management, and security automation.
Key Responsibilities
- Implement and manage SAST and DAST security testing across applications and CI/CD pipelines.
- Integrate application security tools into DevOps/CI-CD pipelines and automate security testing.
- Perform and support application penetration testing to identify security vulnerabilities.
- Analyze SAST/DAST and penetration testing results and validate security findings.
- Work with development teams to understand, prioritize, and remediate identified vulnerabilities.
- Conduct vulnerability assessment and provide recommendations for effective remediation.
- Develop and maintain security gates and policies within CI/CD pipelines.
- Collaborate with DevOps, developers, architects, and security teams to embed security throughout the SDLC.
- Track vulnerabilities through remediation and perform retesting/validation.
- Help reduce false positives and improve the quality of automated security scans.
- Prepare security assessment reports, dashboards, and management-level summaries.
- Support continuous improvement of DevSecOps processes, security automation, and application security controls.
- Stay current with emerging application security threats, vulnerabilities, and industry best practices.
Required Skills
Application Security
- Strong understanding of Application Security and Secure SDLC.
- Hands-on experience with SAST and DAST methodologies.
- Experience in Web Application Security and API Security.
- Good knowledge of common vulnerabilities including OWASP Top 10.
- Understanding of vulnerability severity, risk assessment, and remediation.
SAST / DAST Tools
Experience with one or more application security tools such as:
- SonarQube
- Checkmarx
- Fortify
- Veracode
- Snyk
- GitLab SAST/DAST
- Burp Suite
- OWASP ZAP
- Similar SAST/DAST and application security tools.
DevSecOps / CI-CD
- Hands-on experience with CI/CD pipelines.
- Good understanding of Jenkins, GitLab CI/CD, Azure DevOps, GitHub Actions, or similar tools.
- Experience integrating security scanning into automated build and deployment pipelines.
- Understanding of Docker/Kubernetes and cloud environments is an advantage.
- Experience with scripting/automation using Python, PowerShell, or Shell scripting is preferred.
Penetration Testing
- Knowledge of Web Application and API Penetration Testing.
- Ability to identify and validate common security vulnerabilities.
- Familiarity with tools such as Burp Suite, OWASP ZAP, Nmap, and similar security testing tools.
- Understanding of authentication, authorization, session management, input validation, and API security.
