20 Sep
|
peopleplus professional services
|
Bengaluru
20 Sep
peopleplus professional services
Bengaluru
Company Description PEOPLEplus Professional Services Pvt. Ltd. is a leading resource support company in the IT segment, partnering with top-tier high technology organizations. The company focuses on critical domains such as Embedded, Telecom, Storage, DSP, Wireless, Multimedia, EDA, and VLSI, offering specialized talent and project support.
As a trusted resourcing partner, PEOPLEplus provides opportunities to work on cutting-edge technologies and complex engineering challenges. Team members benefit from exposure to diverse projects, dynamic client environments, and ongoing professional growth.
General Function/Role Purpose:
The DevSecOps Engineer is responsible for identifying, assessing, and helping to remediate security fi ndings and threats while driving automation across the multiple vulnerabilities scanners. Including secure development lifecycle, CSPM, DSPM and pentests results. This role blends hands-on application security expertise with a robust focus on security tooling, integration into CI/CD pipelines, and developer enablement to ensure scalable and continuous security practices across multiple environments and products.
Primary Duties:
- Operate and optimize automated scanning tools (e.g., SAST, DAST, SCA, IaC, ASPM, etc.) to continuously identify security fl aws in applications and infrastructure across multiple product environments
- Develop and maintain workfl ows and playbooks for triage, validation, prioritization, and remediation of vulnerabilities
- Develop automation fl ows using dedicated automation tool to support security activities
- Collaborate closely with engineering, DevOps,
and product teams to track and drive timely remediation of vulnerabilities across our infrastructures, products environments and our code
- Drive adoption of secure coding practices through training, tooling, and documentation.
- Automate vulnerability tracking and reporting using ticketing systems (e.g. Jira) and dashboards to improve visibility and accountability.
- Maintain and enforce vulnerability SLAs and remediation timelines in alignment with internal policies and industry standards
- Continuously evaluate and improve the efficiency, accuracy, and developer-friendliness of the vulnerability management process
- Own and maintain our internal security posture and risk security score
Knowledge, Skills, and Abilities Required
- Strong background in security analysis and familiarity with coding. The ideal candidate should be able to conduct code reviews, identify vulnerabilities, and provide actionable feedback to development teams to enhance security.
- Bachelor’s degree in Computer Science or related field preferred
- Relevant certifications in the cybersecurity fi eld highly desirable
- 8+ years of experience in security related roles: such as application security engineer, Pentester, etc.
- Experience in information security risk analysis, application security and vulnerability management.
- Good written communication and presentation skills with the ability to present security issues to a variety of audiences
- Must be self-directed, able to manage individual projects or act as part of a larger team
Working Conditions Hybrid, Normal office environment.
📌 Principal DevSecOps Engineer (Bengaluru)
🏢 peopleplus professional services
📍 Bengaluru