DevSecOps Security Engineer
Posted Updated
The DevSecOps Security engineer ensures that every step of the software development lifecycle (SDLC) follows security best practices. They are also responsible for guiding the teams to adhere to secure coding principles and aid in testing the application against security risks/parameters before release.
- Drive the implementation of security testing (Secrets Scanning/ SAST / DAST / SCA/IAC/Container Scanning/ AI Security)
- Assist teams in triaging and addressing application security vulnerabilities.
Support integration of security tools into CI / CD pipelines. (Tekton, Cloud Build, Github actions etc.)
- Define and publish security requirements from a DevSecOps perspective.
Prioritizing vulnerabilities discovered along with recommending remediation timeline.
- Collaborate with cross-functional teams to ensure security best practices are followed throughout the software development lifecycle.
- Monitoring and analyzing vulnerability trends to identify focused actions like training, bulk fix, etc.
- Stay up to date with the latest security trends and technologies to continuously improve security processes
- Provide security training and guidance to development teams on secure coding practices and security awareness
Qualifications required:
- Bachelor (undergraduate) degree in a relevant field (Computer Science, Cybersecurity, Software Engineering, or others) OR an equivalent combination of education, training, and experience.
- Minimum of 3 years of professional experience with any combination of at least 2 technical disciplines, including the following: application security, cloud security, vulnerability management, secure development methodologies, identity management.
- Preferred - Cybersecurity / DevSecOps certifications
- Willingness to work in flexible timings to support global customers / collaboration.
Skillset required:
- Experience in security testing (SCA, SAST, DAST, Container Scanning, IaC, etc), and their integration into CI/CD.
- Provide technical expertise in fixing the vulnerabilities. (e.g. Knowledge of OWASP Top 10).
- Excellent communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
- Experience in integrating, monitoring and improving DevSecOps tools and processes, automate routine tasks and improve system reliability.
- Experience in writing scripts in languages such as Golang, Shell Script, Python, YAML etc.
- Experience in DevOps related tools, pipelines, platforms, registries and version control systems.
- Power-user of AI tools to boost productivity and quality of DevSecOps processes.
- Basic understanding of network and web related protocols (such as TCP/IP, UDP, HTTP, HTTPS, protocols)
- Good knowledge of Agile processes (planning/standups/retros etc.) and interact with cross functional teams.