07 Aug
|
Cognizant
|
Pune
Role Summary
Embeds the client's security and compliance requirements into Flowsource pipelines and the control plane configuring SAST (Checkmarx), SCA (Prisma Cloud), container image scanning, IaC scanning, and Veracode to enforce policy-as-code aligned to the client's compliance framework (SOC 2, PCI-DSS, HIPAA, ISO 27001). Owns the security quality gates, vulnerability disclosure workflows, and the leadership-facing compliance dashboards inside Flowsource. Configures tooling against client-owned policy; does not set policy.
Key Responsibilities
- Configure SAST (Checkmarx), SCA (Prisma Cloud), image scanning, IaC scanning, and Veracode integrations inside Flowsource pipeline templates.
- Codify the client's security policy as enforceable gates severity thresholds, allow/deny lists, exception workflows.
- Operate the vulnerability triage and disclosure workflow surfaced inside Flowsource; route findings to the right squad with SLA.
- Build and maintain leadership-facing compliance dashboards (open critical, mean time to remediate, control coverage).
- Partner with DevOps & Pipeline Integrator to keep pipeline gates consistent across every onboarded application.
- Support client audit readiness by exporting Flowsource evidence packs (scan history, gate enforcement, remediation timelines).
- Stay aligned with the client compliance framework (SOC 2 / PCI / ISO / HIPAA) and surface any gaps to the FDE Lead.
- Required Skills & Experience
- 6+ years application security or DevSecOps engineering experience.
- Hands-on with at least two of: Checkmarx, Prisma Cloud, Veracode, Snyk, SonarQube security profiles.
- Working knowledge of at least one compliance framework: SOC 2, PCI-DSS, HIPAA, ISO 27001.
- Container image scanning and IaC scanning experience (Trivy, Checkov, tfsec, kube-bench helpful).
- Comfortable building exec-facing reporting; able to talk policy with security leadership and tooling with developers.
📌 Security & Compliance Engineer (Pune)
🏢 Cognizant
📍 Pune