Senior Application Security (DevSecOps) Engineer

4 - 8 years

5 - 9 Lacs

Posted:3 days ago| Platform: Foundit logo

Apply

Skills Required

CI/CD pipeline

Work Mode

On-site

Job Type

Full Time

Job Description

Senior Application Security (DevSecOps) Engineer

Responsibilities

  • Act as the

    Application Security SME

    for our ongoing GitHub migration program.
  • Integrate SAST (Static Application Security Testing), SCA (Software Composition Analysis), IaC (Infrastructure as Code) scanning, and DAST (Dynamic Application Security Testing) tools

    into CI/CD pipelines (e.g., GitHub Actions, Jenkins, GitLab CI).
  • Drive security initiatives within

    GitHub Enterprise Security

    (code scanning, secret scanning, dependency management).
  • Collaborate with development, SRE, and cloud teams

    to embed security into the SDLC (Software Development Life Cycle) and DevOps workflows.
  • Manage and optimize CSPM (Cloud Security Posture Management) tools

    (e.g., Rapid7 ICS, Prisma Cloud, Wiz, Lacework) to enforce security policies across cloud assets.
  • Create and maintain

    reusable security automation patterns and scripts

    (e.g., GitHub Actions, Terraform modules).
  • Support

    application security reviews

    and recommend mitigations for security findings.
  • Build

    dashboards and metrics

    to track pipeline coverage, tool effectiveness, and SLA adherence.
  • Provide guidance and hands-on support during

    secure development, threat modeling, and remediation planning

    .
  • Advocate for

    security best practices

    in engineering forums and architecture discussions.

Skills & Experience

Required:

  • experience

    in a DevSecOps, Application Security, or DevOps Security role.
  • Strong working knowledge of:

  • Extensive experience in

    GitHub Enterprise

    and related security capabilities, especially security tool integrations and automations.
  • CI/CD pipeline integration of security tooling.

  • Cloud platforms (AWS, Azure, GCP)

    and hands-on experience with

    CSPM solutions

    .
  • Working experience in

    Application security tools (SAST, DAST, SCA, IaC)

    .
  • Sound working experience in

    scripting and programming languages

    .
  • Experience collaborating with software engineers, cloud teams, and SREs in a security capacity.
  • Good understanding of

    OWASP Top 10, secure coding practices, and the DevOps lifecycle

    .
  • Proficient in

    scripting (e.g., Python, Bash)

    and

    automation (e.g., GitHub Actions, Terraform, Ansible)

    .

Nice to Have:

  • Experience with

    threat modeling or security architecture reviews

    .
  • Knowledge of

    container security and Kubernetes security controls

    (e.g., Kube-bench, Trivy).
  • Exposure to

    risk and vulnerability management workflows

    (e.g., Jira, ServiceNow, Qualys).

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Pearson logo
Pearson

Higher Education

London Hoboken

RecommendedJobs for You

Bengaluru, Karnataka, India

Chennai, Tamil Nadu, India