Job Summary
We are seeking an Application & DevSecOps Security Engineer to integrate security throughout the software development lifecycle using modern DevSecOps practices, container security, software supply chain security, and automated vulnerability management.
Key Responsibilities
- Implement DevSecOps pipelines.
- Perform SAST, DAST, SCA, and IaC scanning.
- Secure containerized applications.
- Implement software supply chain security.
- Secure Kubernetes environments.
- Integrate security into CI/CD pipelines.
- Develop security automation.
- Conduct application threat modeling.
- Support secure code reviews.
- Implement security policies.
Required Skills
- DevSecOps
- GitHub Advanced Security
- Checkmarx
- Veracode
- Snyk
- Trivy
- Docker Security
- Kubernetes Security
- OWASP Top 10
- SAST
- DAST
- SCA
- CI/CD
- GitHub Actions
- Terraform
Preferred Skills
- SBOM
- Sigstore
- Cosign
- Python
- Open Policy Agent (OPA)
- Kyverno
Mandatory Skills
- DevSecOps
- SAST
- DAST
- SCA
- Kubernetes Security
- Docker Security
- GitHub Advanced Security
- Snyk
- Terraform
- OWASP Top 10