09 Sep
|
Atos
|
Bengaluru
We are looking for a highly experienced Senior DevSecOps Security Engineer to lead cybersecurity testing initiatives across web applications, APIs, CI/CD pipelines, and software supply chain environments. The ideal candidate will have strong hands-on experience integrating security into the SDLC and driving secure-by-design practices across development, QA, and production environments. Key Responsibilities
- Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs.
- Perform and review Static Application Security Testing (SAST), including detailed source code review.
- Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments.
- Design and execute fuzzing activities for applications and APIs.
- Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components.
- Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities.
- Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes.
- Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices.
- Define and implement security testing practices across the SDLC.
- Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles.
- Identify security test scenarios during sprint planning.
- Create, maintain, and automate security test cases.
- Execute and validate security test cases across Dev, UAT, and Production promotion stages.
- Review and validate remediation activities and provide risk-based recommendations.
- Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance.
Required Skills and Experience
- 5–7 years of experience in Application Security Testing, DevSecOps.
- Strong hands-on experience in web application security testing and API security testing.
- Proven experience in:
o SAST (secure code review)
o DAST o Fuzzing o Software Composition Analysis (SCA)
o CI/CD pipeline security testing o Software supply chain security testing
- Strong understanding of SDLC, secure coding practices, and shift-left security.
- Experience creating and automating security test cases in agile/sprint-based environments.
- Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
- Experience working with development, DevOps, QA, and product teams.
- Solid analytical, communication, and stakeholder management skills.
Tools
Knowledge
- JFrog
- SonarQube
- Burp Suite
- Nessus
- XRAY
- JIRA
- Microsoft Threat Modeling Tool
- Postman Preferred Qualifications
- Experience with cloud platforms such as AWS, Azure, or GCP.
- Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security.
- Experience integrating security tools into CI/CD pipelines.
- Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.
📌 Sr. Devsecops Security Engineer (Bengaluru)
🏢 Atos
📍 Bengaluru