We are hiring a DevSecOps Engineer to build and maintain secure CI/CD pipelines and integrate security practices across the software development lifecycle. The role focuses on ensuring secure, compliant, and scalable software delivery.
Key Responsibilities
- Design and maintain secure CI/CD pipelines using Jenkins and GitLab
- Implement security controls, SBOM generation, and vulnerability management
- Integrate security scanning tools (SonarQube, CodeQL, etc.)
- Secure container environments (Docker, Kubernetes)
- Manage artifact repositories and enforce supply chain security
- Develop automation scripts (Python/PowerShell)
- Ensure compliance with security standards and regulations
- Collaborate with Dev, QA, and Security teams to fix vulnerabilities
Required Qualifications
- Experience in designing , maintaining secure CI/CD using Jenkins & GitLab
- Experience in Software Bill of Materials (SBOM) CycloneDX, SPDX format
- Experience in vulnerability management & vulnerability scanning
- Experience in tracking tools (Defect Dojo or similar)
- Robust experience in Python or PowerShell scripting
- Experience in security scanning tools (SonarQube, TICS, CodeQL)
- Experience in Docker, Kubernetes, RBAC
- Understanding of VMware infrastructure security
- Experience in Docker, Kubernetes, RBAC & vulnerability scanning
- Understanding of VMware infrastructure security
- Experience working in Agile environments using JIRA/SCRUM/KANBAN
- Bachelors or Master’s degree in CSE, IT, Cybersecurity or related fields
- Knowledge supporting cybersecurity regulations and standards(Good to have)
- Knowledge on software license management & SPDX license identifiers(good to have)