DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs
Alignity Solutions · Shaikpet, India ·
- Employment
- Contract
- Category
- Security
- Experience
- 3+ years
Alignity Solutions · Shaikpet, India ·
Codincity Digital Technologies · Chennai, Tamil Nadu, India
ncsaustralia · Melbourne, VIC, au
ARYAN SOLUTIONS PTE. LTD. · Singapore
Axpo · Madrid, ES
Contract-to-hire senior application security consultant role in Hyderabad (hybrid): integrating SAST/DAST tools like Checkmarx, Veracode, Fortify, Burp Suite, and OWASP ZAP into CI/CD pipelines, performing penetration tests, triaging findings, and guiding remediation and secure coding practices for a Deloitte client engagement.
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Roles & Responsibilities:
As a Consultant, you are responsible for performing following activities as a SAST/DAST professional:
· Integrate SAST and DAST tools into CI/CD pipelines to automate security testing throughout the development lifecycle.
· Perform regular static (SAST) and dynamic (DAST) security assessments on applications to identify vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.
· Analyze scan results, triage findings, and provide actionable remediation guidance to development teams.
· Collaborate with developers to ensure secure coding practices and support secure design reviews.
· Define and maintain security roles, responsibilities, and ownership between Deloitte and client stakeholders for test preparation, execution, and support.
· Ensure that vulnerabilities are tracked, reported, and resolved in accordance with organizational policies and client requirements.
· Conduct root cause analysis (RCA) workshops and publish performance and security testing reports.
· Stay current with industry trends, emerging threats, and advancements in SAST/DAST tools and methodologies.
Required skills
Qualification
· Bachelor's degree or higher in Computer Science, or equivalent experience.
· Security certifications such as CSSLP, CEH, or similar.
· Experience with cloud-native application security and container security.
· Knowledge of regulatory and compliance requirements related to application security.
Good to have:
allwynuk · Watford, England, United Kingdom