JD - DevSecOps Security Engineer
JD - DevSecOps Security Engineer
Responsibilities:
Implement, configure, and maintain security testing tools within CI/CD pipelines, including
SAST, DAST, SCA, and container security scanning tools while ensuring seamless integration
with existing workflows
Conduct comprehensive security assessments, vulnerability testing, and code reviews
throughout the development lifecycle, providing detailed remediation guidance and tracking
security improvements
Design and implement security automation processes, including automated vulnerability
scanning, compliance checking, and security testing integration within DevOps workflows
Review and assess Infrastructure as Code (IaC) implementations, cloud configurations, and
deployment pipelines while collaborating with cloud infrastructure teams to ensure secure
resource provisioning
Monitor and analyze security testing results, maintain security metrics dashboards, and
generate regular reports on application security posture and trends
Work closely with development teams to implement secure coding practices, conduct security
training sessions, and provide guidance on vulnerability remediation
Develop and maintain security documentation, including secure coding guidelines, security
testing procedures, and implementation standards for security tools
Collaborate with security architects and development teams to implement security
requirements and controls throughout the application development lifecycle
Support incident response activities related to application security issues and provide technical
expertise during security incidents
Evaluate and recommend new security tools and technologies to enhance the DevSecOps
security program
Qualifications: