18 Aug
|
2COMs
|
Bengaluru
Application Support Engineer (SAST &
- DAST, DevSecOps)
Experience: 7-12 years
Location: Bangalore/Hyderabad/Pune
Summary
This pivotal role focuses on strengthening enterprise application security by leveraging a comprehensive suite of testing methodologies, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secrets Detection, and Dynamic Application Security Testing (DAST). The successful candidate will act as a catalyst for embedding security into the Software Development Life Cycle (SDLC), ensuring seamless integration within CI/CD workflows. By overseeing vulnerability validation, managing Software Bill of Materials (SBOM), and driving risk-based remediation strategies, this position is essential for maintaining robust security postures and delivering actionable security metrics to stakeholders.
Responsibilities
- Execute ongoing and targeted security assessments utilizing advanced SAST, SCA, Secrets Detection, and DAST technologies.
- Analyze security alerts to verify accuracy, filter out false positives, and assist development teams in resolving identified vulnerabilities.
- Embed automated security scanning mechanisms directly into CI/CD pipelines to enforce strict secure development gates.
- Oversee the creation of SBOMs, monitor open-source dependency risks, track Common Vulnerabilities and Exposures (CVEs), and generate reports on vulnerability exposure.
- Monitor and manage remediation Service Level Agreements (SLAs), Turnaround Time (TTD), and Time to Remediate (TTR) metrics alongside key application security performance indicators.
- Collaborate closely with development, DevSecOps, and platform engineering units to facilitate effective remediation and foster a culture of continuous security enhancement.
- Contribute to security evaluation efforts, optimize scanning tools, produce executive reports, and lead initiatives to empower developers with security best practices.
Requirements
- Possess between 2-6 years of skilled experience within Application Security, Secure SDLC frameworks, or DevSecOps environments.
- Demonstrate practical expertise in managing enterprise-level AppSec scanning platforms and executing vulnerability management lifecycles.
- Show proven ability to integrate security testing protocols into CI/CD pipelines and cloud-native infrastructure.
- Maintain a deep understanding of the OWASP Top 10, secure coding standards, and the principles of software supply chain security.
Technical Skills &
- Tool Experience
- SAST: Proficiency with Checkmarx, Veracode, Fortify, SonarQube, or GitHub Advanced Security.
- SCA &
- SBOM:
Experience utilizing Fortify, Checkmarx, Snyk, or Black Duck for dependency analysis.
- DAST &
- API Security: Hands-on knowledge of Fortify, Checkmarx, Burp Suite, Invicti, or Acunetix.
- Secrets Detection: Familiarity with GitGuardian or GitHub Secret Scanning capabilities.
- DevSecOps: Competence in Azure DevOps, GitHub Actions, Jenkins, or GitLab CI/CD.
- Container &
- Cloud Security: Knowledge of Prisma Cloud, Wiz, Aqua, or Microsoft Defender for Cloud.
- Reporting &
- ITSM: Skills in ServiceNow, Power BI, and Grafana for data visualization and ticket management.
📌 Application Security Engineer (SAST & DAST, DevSecOps) (Bengaluru)
🏢 2COMs
📍 Bengaluru