27 Aug
|
Acme Services Private
|
Panvel
27 Aug
Acme Services Private
Panvel
Job Description:
- Integrate security controls and automated security testing into CI/CD pipelines.
- Implement and promote Secure Software Development Lifecycle (SSDLC) and DevSecOps best practices.
- Configure and manage security tools for:
- Static Application Security Testing (SAST)
- Agile Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Container and dependency vulnerability scanning
- Work with tools such as SonarQube, Checkmarx, Snyk, Fortify, Veracode, OWASP ZAP, or similar security platforms.
- Identify, prioritize, and support remediation of application, infrastructure, and cloud security vulnerabilities.
- Perform or support threat modeling, security reviews, and risk assessments.
- Secure Infrastructure-as-Code (IaC) using tools and practices for Terraform, CloudFormation, ARM templates, Kubernetes manifests, etc.
- Implement security controls for containerized applications and Kubernetes environments.
- Collaborate with developers, DevOps engineers, cloud teams, and security teams to establish security-by-design practices.
- Automate security checks, compliance validation, and vulnerability reporting using scripting and automation.
- Monitor security findings and support vulnerability management and remediation processes.
- Ensure applications and infrastructure align with OWASP Top 10, security standards, and organizational policies.
- Support security compliance initiatives, audits, and evidence collection.
- Stay updated with emerging security threats, vulnerabilities, cloud security practices, and DevSecOps technologies.
📌 DevSecOps Specialist (Panvel)
🏢 Acme Services Private
📍 Panvel