09 Sep
|
JungleWorks
|
Punjab
09 Sep
JungleWorks
Punjab
Job Title: Cybersecurity (Application Security / DevSecOps)
Location: Onsite (Mohali)
About the Role
We are looking for a hands-on Cybersecurity professional with 6 months to 1 year of practical experience who has already worked with real-world security tools through previous employment, internships, training, or personal projects.
This is not a theory role.
You will be responsible for implementing, enforcing, and monitoring security processes across our engineering stack. You will sit between DevOps and Developers, ensuring security is built into the system — not added later.
If you like ownership, execution, and accountability, this role is for you.
What You’ll Do (No Excuses, Real Work)
Actively run SAST & DAST scans on applications and APIs.
Implement security checks inside CI/CD pipelines (not just suggest them).
Ensure security processes are followed, flagged, and fixed — no silent bypasses.
Work directly with Developers & DevOps to close vulnerabilities.
Validate fixes and re-test until closure.
Maintain security reports, scan results, and remediation status.
Identify gaps in current security workflows and help improve them.
Own security hygiene and make sure it doesn’t slip.
What We Expect (Must-Have)
Proven hands-on experience with SAST / DAST through:
Internships
Industry training
Academic or personal security projects
Working knowledge of application security processes.
Familiarity with OWASP Top 10 vulnerabilities.
Understanding of CI/CD pipelines and how security fits into them.
Ability to read scan outputs, understand risks, and communicate fixes clearly.
Strong follow-through mindset — issues are tracked until resolved.
Comfortable calling out when processes are not being followed.
Good to Have (Strong Advantage)
Hands-on exposure to tools like:
OWASP ZAP, Burp Suite
Snyk, SonarQube, Trivy
Basic knowledge of cloud environments (AWS/GCP/Azure).
Experience with Docker, Kubernetes, or container security.
Understanding of API security, authentication, and authorization.
Any real-world security assessment, PoC, or bug-finding experience.
Who Should NOT Apply
If you only know security theory.
If you’ve never run a real security scan.
If you avoid accountability or ownership.
If process enforcement feels “too strict” for you.
What You’ll Gain
Real-world DevSecOps experience.
Exposure to production-grade security workflows.
Direct collaboration with engineering & DevOps teams.
Ownership of security processes that actually matter.
Solid foundation for roles in Application Security / DevSecOps.
Bonus Points
GitHub with security projects
Reports from security tools you’ve used
Blog posts / write-ups / labs / CTF experience
📌 Cyber Security (Punjab)
🏢 JungleWorks
📍 Punjab