Senior DevSecOps Engineer

Posted 2hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

DevSecOps Engineer enhancing application security and embedding DevSecOps practices across the development lifecycle. Collaborating with teams to drive secure software delivery in a remote role.

Responsibilities:

  • Identify, assess, and remediate application security vulnerabilities across web, API, and cloud environments.
  • Integrate and maintain security controls in CI/CD pipelines (e.g., SAST, DAST, SCA, container scanning, IaC security).
  • Collaborate with development and operation teams to embed secure coding practices and ensure “shift-left” security.
  • Conduct and support secure code reviews, threat modeling, and application risk assessments.
  • Develop automation and scripts to enforce security checks in the pipeline.
  • Monitor, triage, and remediate findings from application security tools.
  • Stay current with industry trends, frameworks, and emerging threats (OWASP, MITRE ATT&CK, NIST).
  • Contribute to security guidelines, standards, and training for developers.

Requirements:

  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or equivalent experience.
  • Proven experience in DevSecOps, Application Security, or Secure Software Development(3+ years).
  • Good programming skills in programming languages such as PHP, JavaScript, Python, or Java.
  • Hands-on experience with CI/CD tools(GitHub Actions, GitLab CI/CD, Jenkins, CircleCI, etc.).
  • Practical experience with SAST, DAST, SCA, IAST, and related security tooling.
  • Understanding of cloud security practices.
  • Familiarity with container security (Docker, Kubernetes).
  • Strong knowledge of OWASP Top 10, secure coding principles, and common attack vectors.
  • Ability to communicate security requirements effectively to developers and stakeholders.