Lead II - Software Security Tester - DevSecOps Security (Thiruvananthapuram)

Lead II - Software Security Tester - DevSecOps Security (Thiruvananthapuram)

06 Aug
|
UST
|
Thiruvananthapuram

06 Aug

UST

Thiruvananthapuram

Must-Have Skills

- Min 10-13yrs years experience in Dev SecOps or DevOps along with Application Security, or Security Engineering, with lead-level experience
- Expert-level CI/CD pipeline engineering building, configuring, and optimising end-to-end ssecurity-integrated pipelines (any major CI/CD platform; GitLab CI/CD preferred)
- SAST hands-on experience implementing and tuning static analysis tools ( Semgrep preferred)
- DAST proficiency with agile application security testing tools ( Burp Suite and OWASP ZAP preferred)
- SCA & SBOM experience with software composition analysis and SBOM generation/tracking ( Dependency-Track , CycloneDX/CDXGen preferred)
- Secrets scanning experience with secrets detection tools integrated into CI pipelines ( Detect-Secrets preferred)
- Container & image scanning experience with container security scanning tools ( Trivy preferred)
- Vulnerability management platforms operating centralised vulnerability aggregation and tracking platforms, managing triage, deduplication, false positive handling, and severity-based SLAs ( DefectDojo preferred)
- Secrets management experience with vault-based secrets management, rotation policies, and least-privilege enforcement ( HashiCorp Vault preferred)
- Observability & security monitoring experience with observability platforms for security log monitoring, ing, and dashboarding ( Datadog preferred)




- Sensitive data detection hands-on experience with PII detection and redaction in application logs across production and non-production environments ( Datadog Sensitive Data Scanner / SDS preferred)
- Client-side security experience with client-side web script monitoring and protection tools ( SourceDefense preferred)
- Automated dependency management experience with automated dependency update tools, including MR review and pipeline failure triage ( Dependabot or Renovate preferred)
- Infrastructure scanning experience with infrastructure vulnerability scanning tools ( Qualys preferred)
- Code quality experience with code quality and static analysis platforms ( SonarQube preferred)
- Infrastructure as Code experience managing security configurations through IaC tools ( Terraform preferred)
- Container & cloud security strong knowledge of Docker , Kubernetes , and securing containerised workloads
- Security standards expertise deep understanding of OWASP Top 10, CVSS scoring, CWE classification, ASVS, and secure SDLC practices
- Governance & process design proven ability to define security policies, release criteria, RBAC models, and audit-ready documentation
- Leadership & communication ability to influence engineering teams, present security risk assessments to stakeholders, and mentor junior security engineers

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Lead II - Software Security Tester - DevSecOps Security (Thiruvananthapuram)
🏢 UST
📍 Thiruvananthapuram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead ii - software security tester - devsecops security (thiruvananthapuram) / thiruvananthapuram

Subscribe to this job alert:

Get the latest job offers by email for: lead ii - software security tester - devsecops security (thiruvananthapuram) / thiruvananthapuram