We have an excellent opportunity for Sr. DevSecOps Engineer role in Bengaluru. Please apply only if you're an immediate joiner. Kindy share your updated cv on
[email protected] along with your details: Current CTC, Expected CTC, Notice Period, Current Location.
Role & responsibilities
- Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs.
- Perform and review Static Application Security Testing (SAST), including detailed source code review.
- Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments.
- Design and execute fuzzing activities for applications and APIs.
- Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components.
- Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities.
- Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes.
- Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices.
- Define and implement security testing practices across the SDLC.
- Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles.
- Identify security test scenarios during sprint planning.
- Create, maintain, and automate security test cases.
- Execute and validate security test cases across Dev, UAT, and Production promotion stages.
- Review and validate remediation activities and provide risk-based recommendations.
- Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance.
Required Skills and Experience
- 5-7 years of experience in Application Security Testing, DevSecOps.
- Robust hands-on experience in web application security testing and API security testing.
- Proven experience in
- SAST (secure code review)
- DAST
- Fuzzing
- Software Composition Analysis (SCA)
- CI/CD pipeline security Testing
- Software supply chain security testing
- Strong understanding of SDLC, secure coding practices, and shift-left security.
- Experience creating and automating security test cases in agile/sprint-based environments.
- Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
- Experience working with development, DevOps, QA, and product teams.
- Strong analytical, communication, and stakeholder management skills.
Tools Knowledge
- JFrog
- SonarQube
- Burp Suite
- Nessus
- XRAY
- JIRA
- Microsoft Threat Modeling Tool
- Postman
Preferred Qualifications
- Experience with cloud platforms such as AWS, Azure, or GCP.
- Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security.
- Experience integrating security tools into CI/CD pipelines.
- Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications
- US customer timings. 2:30 PM-11:30 PM IST
📌 Sr. DevSecOps Security Engineer(Immediate Joiners Only) (Bengaluru)
🏢 Atos
📍 Bengaluru