27 Sep
|
algoleap
|
Hyderabad
27 Sep
algoleap
Hyderabad
Roles & Responsibilities As a Consultant, you are responsible for performing following activities as a SAST/DAST professional:
· Integrate SAST and DAST tools into CI/CD pipelines to automate security testing throughout the development lifecycle.
· Perform regular static (SAST) and dynamic (DAST) security assessments on applications to identify vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.
· Analyze scan results, triage findings, and provide actionable remediation guidance to development teams.
· Collaborate with developers to ensure secure coding practices and support secure design reviews.
· Define and maintain security roles, responsibilities, and ownership between Deloitte and client stakeholders for test preparation, execution, and support.
· Ensure that vulnerabilities are tracked, reported, and resolved in accordance with organizational policies and client requirements.
· Conduct root cause analysis (RCA) workshops and publish performance and security testing reports.
· Stay current with industry trends, emerging threats, and advancements in SAST/DAST tools and methodologies.
Required Skills
- Hands-on experience with leading SAST and DAST tools (e.g., Checkmarx, Veracode, Fortify, Burp Suite, OWASP ZAP).
- Solid understanding of secure software development lifecycle (SSDLC)
principles and OWASP Top 10 vulnerabilities.
- Experience integrating security testing into CI/CD pipelines (e.g., Jenkins, Azure DevOps, GitLab CI).
- Ability to interpret and communicate vulnerability findings and remediation steps to technical and non-technical stakeholders.
- Familiarity with both black-box (DAST) and white-box (SAST) testing methodologies.
Qualification · Bachelor's degree or higher in Computer Science, or equivalent experience. · Security certifications such as CSSLP, CEH, or similar.
· Experience with cloud-native application security and container security.
· Knowledge of regulatory and compliance requirements related to application security.
Good To Have
- Experience participating in or conducting security architecture reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
- Proficiency in performing threat modeling exercises (e.g., using STRIDE, PASTA, or other frameworks) to systematically identify, document, and prioritize potential threats and attack vectors in applications and systems.
- Skill in translating threat model findings into actionable SAST/DAST test cases and ensuring that identified threats are adequately tested and mitigated.
📌 DevSecOps Engineer (SAST/DAST) (Hyderabad)
🏢 algoleap
📍 Hyderabad