DevSecOps Security Analyst – MID

Posted 5hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

DevSecOps Security Analyst ensuring application security practices within development processes. Engaging with teams on secure coding and vulnerability management.

Responsibilities:

  • Identify vulnerabilities in source code and assist in defining remediation plans;
  • Monitor and support the secure coding process;
  • Assess results from security tools such as SAST, DAST, and SCA;
  • Perform threat modeling and elicit architectural and development security requirements;
  • Support developers in resolving vulnerabilities and implementing security guardrails;
  • Participate in governance processes and track code and architectural vulnerabilities;
  • Use secure development frameworks and best practices, including OWASP ASVS, SAMM, WSTG, and MASVS;
  • Deliver training and awareness initiatives on Information Security;
  • Act as a Security Champion, promoting a security-first culture across technical teams;
  • Work collaboratively with development, architecture, operations, and security teams;
  • Support the implementation and monitoring of security practices in CI/CD pipelines using Azure DevOps.

Requirements:

  • Experience in Application Security and DevSecOps practices;
  • Knowledge of identifying and remediating vulnerabilities in source code;
  • Hands-on experience with SAST, DAST, and SCA tools;
  • Experience with Azure DevOps and integrating security into CI/CD pipelines;
  • Experience in threat modeling and defining security requirements;
  • Familiarity with OWASP frameworks (ASVS, SAMM, WSTG, MASVS);
  • Experience with Secure Code Review processes and security across the development lifecycle;
  • Strong analytical skills and a consultative approach when working with development teams;
  • Knowledge of governance and vulnerability management processes;
  • Experience serving as a Security Champion;
  • Experience in critical and high-availability environments;
  • Knowledge of security automation;
  • Experience with cloud environments and secure architecture.