DevSecOps Application Security Engineer
  • Nityo Infotech
4 Days Ago
NA
Yearly
Richardson-TX
6-10 Years
Required Skills: SDLC, DevSecOps practices, microservices, API, cloud security
Job Description
Required Skill and Experience
• Application Security Testing: Conduct SAST/SCA using GHAS and DAST using Burp Suite; validate and classify vulnerabilities aligned with OWASP.
• DevSecOps & Integration: Integrate GHAS into CI/CD, automate scans across SDLC, configure policies, reduce false positives, and enable shift-left security with development teams.
• Vulnerability Management: Analyze findings, provide remediation guidance, track vulnerabilities through lifecycle, and support risk-based prioritization.
• Reporting & Stakeholder Management: Prepare technical and executive reports, communicate findings with stakeholders, and support audits, compliance, and AppSec initiatives.
 
Preferred Skill and Experience
• Security Advisory & Review: Conduct secure code reviews and architecture level assessments; Coordinate with development teams on secure coding and mitigation strategies.
• Knowledge Of: SDLC and DevSecOps practices, microservices/API/cloud security, strong analytical/problem-solving skills, and stakeholder communication/consulting experience.

Good to Have:
• Exposure to SAST (Fortify, SonarQube), DAST (Netsparker, Fortify on Demand), and SCA (BlackDuck, Dependabot) tools
• Certifications: CEH, OSCP, GWAPT, CSSLP, CISSP
• Experience in threat modeling and architecture reviews

Jobseeker

Looking For Job?
Search Jobs

Recruiter

Are You Recruiting?
Search Candidates