Sr. Devsecops Security Engineer
Atos Bengaluru, Karnataka, India
Business Consulting and Services · 10,001+ employees
About the role
Lead and execute comprehensive cybersecurity testing, including SAST, DAST, and fuzzing, across web applications and CI/CD pipelines. Collaborate with development and DevOps teams to integrate security practices into the SDLC and mentor junior engineers on security standards.
What they look for
Requirements
Requires 5-7 years of experience in DevSecOps and application security testing with proficiency in various security tools and methodologies. Candidates must have a strong understanding of secure coding practices, CI/CD pipeline security, and software supply chain risks.
Full description
We are looking for a highly experienced Senior DevSecOps Security Engineer to lead cybersecurity testing initiatives across web applications, APIs, CI/CD pipelines, and software supply chain environments. The ideal candidate will have strong hands-on experience integrating security into the SDLC and driving secure-by-design practices across development, QA, and production environments.
Key Responsibilities
- Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs.
- Perform and review Static Application Security Testing (SAST), including detailed source code review.
- Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments.
- Design and execute fuzzing activities for applications and APIs.
- Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components.
- Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities.
- Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes.
- Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices.
- Define and implement security testing practices across the SDLC.
- Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles.
- Identify security test scenarios during sprint planning.
- Create, maintain, and automate security test cases.
- Execute and validate security test cases across Dev, UAT, and Production promotion stages.
- Review and validate remediation activities and provide risk-based recommendations.
- Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance.
Required Skills and Experience
- 5–7 years of experience in Application Security Testing, DevSecOps.
- Strong hands-on experience in web application security testing and API security testing.
- Proven experience in:
o SAST (secure code review) o DAST o Fuzzing o Software Composition Analysis (SCA) o CI/CD pipeline security testing o Software supply chain security testing
- Strong understanding of SDLC, secure coding practices, and shift-left security.
- Experience creating and automating security test cases in agile/sprint-based environments.
- Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
- Experience working with development, DevOps, QA, and product teams.
- Strong analytical, communication, and stakeholder management skills.
Tools Knowledge
- JFrog
- SonarQube
- Burp Suite
- Nessus
- XRAY
- JIRA
- Microsoft Threat Modeling Tool
- Postman
Preferred Qualifications
- Experience with cloud platforms such as AWS, Azure, or GCP.
- Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security.
- Experience integrating security tools into CI/CD pipelines.
- Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.
Similar roles
-
Information Security Engineer - Cloud Security
Ryanair Group Holdings Wrocław, Lower Silesian Voivodeship, Poland
-
Cybersecurity Threat Analyst - English(US)
Welocalize Arlington, Texas, United States · $112K/yr
-
Cybersecurity Threat Analyst - English(Philippines)
Welocalize Manila, Metro Manila, Philippines · $19K/yr
-
Cybersecurity Threat Analyst - English(India)
Welocalize Delhi, India · $21K/yr
-
Cloud Security Engineer, Product Security
Recorded Future Gothenburg, Västra Götaland County, Sweden
-
Cybersecurity Risk Analyst
Inetum Porto, Portugal