3-6 years of experience in DevSecOps, security engineering, or a hybrid software/security role.
- Hands-on experience with CI/CD pipelines (e.g., Bitbucket Pipelines, Jenkins, GitHub Actions, Azure DevOps)
and integrating security scanning into them.
- Working knowledge of SAST/SCA/container scanning tools (Checkmarx, Snyk, Trivy, or similar).
- Solid scripting ability (Python, PowerShell, or Bash) for automation and tooling integration.
- Practical experience with at least one major cloud platform (AWS, Azure, or OCI); IAM and network security
fundamentals.
- Familiarity with vulnerability management concepts (CVSS, CISA KEV, SLA-based remediation) and ticketing
workflows (Jira).
- Explicit written and verbal communication; comfortable producing formal documentation and presenting findings to technical and non-technical stakeholders.