Security Consultant – Penetration Testing, DevSecOps
Posted 23hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Consultant conducting application, API, cloud, and infrastructure penetration testing for Capgemini’s technology transformation services. Embedding security controls across DevSecOps pipelines and the software development lifecycle.
Responsibilities:
- Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure
- Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities using OWASP, PTES, NIST, and MITRE ATT&CK methodologies
- Identify vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations
- Execute security assessments of microservices, containers, Kubernetes, and cloud-native applications
- Develop proof-of-concepts demonstrating security weaknesses and attack paths
- Prepare detailed technical reports and executive summaries for customers and stakeholders
- Integrate security controls and testing into CI/CD pipelines
- Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions
- Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices
- Participate in security architecture reviews, threat modeling exercises, and secure design assessments
- Automate security testing and compliance validation within DevOps toolchains
- Develop security guardrails and policy-as-code capabilities
- Perform vulnerability triage, risk prioritization, and remediation tracking
- Support continuous security monitoring and risk assessment activities
- Analyze emerging threats, attack techniques, and security trends
- Assist in developing security standards, procedures, and best practices
- Work with engineering, cloud, and infrastructure teams to enhance organizational security posture
- Present findings and recommendations to developers, architects, engineering teams, and leadership
- Provide security consulting throughout the software development lifecycle
Requirements:
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field
- 5-8 years of hands-on cybersecurity experience
- Minimum 3+ years of experience conducting application and API penetration testing
- Experience implementing or supporting DevSecOps initiatives within CI/CD environments
- Strong understanding of Web Application Security, API Security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, Threat Modeling, and Vulnerability Management
- Hands-on experience with Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins
- One or more listed security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty
- Experience with container security (Docker, Kubernetes)
- Experience conducting cloud penetration testing
- Understanding of Infrastructure as Code (Terraform, CloudFormation)
- Familiarity with Red Team methodologies and adversary simulation
- Exposure to Zero Trust Architecture and Secure-by-Design principles
- Experience with AI/LLM security testing is a plus
- Excellent communication, consulting, and stakeholder management skills
Benefits:
- Vacation: 12-25 days, depending on grade
- Company paid holidays
- Personal Days
- Sick Leave
- Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
- Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
- Life and disability insurance
- Employee assistance programs
- Other benefits as provided by local policy and eligibility
- Variable incentives, bonuses, or commissions may be available















