5 - 8 years
0 Lacs
Posted:1 day ago|
Platform:
On-site
Full Time
Urgent opening forDevSecOps (Security test lead) Engineer
Job Description: DevSecOps (Security test lead) Engineer
Experience Level: 58 Years
Budget-6-8LPA
Location: Bangalore, Rohan Tech Park /Mumbai, Mahape
Notice:Immediate to 15 days
Tech stack and Mandatory Skills
Strong expertise in SAST (Static Application Security Testing) & SCA (Software Composition Analysis) tools
Hands?on with Snyk, SonarQube, Checkmarx, Fortify (or equivalent)
Proven ability to identify, triage, and eliminate false positives
Deep understanding of Secure Software Development Lifecycle and CI/CD environments
Solid knowledge of OWASP Top 10, secure coding standards, and API security concepts
Jenkins, GitLab, Azure DevOps
Excellent communication and ability to influence teams
58 years in Application Security or DevSecOps domain
Role Summary
We are seeking a skilled DevSecOps Engineer with strong expertise in Application Security,
SAST, and SCA tools. The ideal candidate will collaborate closely with development and
DevOps teams to integrate security seamlessly into the CI/CD pipeline, identify and
eliminate false positives, and drive vulnerability remediation across multiple business
applications. Hands-on experience in Snyk or equivalent platforms will be a significant
advantage.
Implement and maintain SAST and SCA tools within the CI/CD pipeline for continuous code
scanning.
Analyze scan results, validate and triage false positives, and ensure accuracy of reported
vulnerabilities.
Collaborate with development teams to guide and support remediation of security
vulnerabilities.
Work with DevOps teams to automate security checks and streamline secure build and
deployment processes.
Perform tool integrations (Snyk, SonarQube, Checkmarx, or similar) to improve visibility of
the organization's security posture.
Provide technical guidance and training to developers on secure coding practices.
Participate in threat modeling, secure design discussions, and application architecture
reviews.
Prepare and maintain documentation for processes, standards, and tool usage.
58 years of experience in Application Security or DevSecOps domain.
Strong understanding of SAST and SCA tools (e.g., Checkmarx, Fortify, SonarQube, Snyk, or
similar).
Proven ability to identify, analyze, and manage false positives effectively.
Good understanding of Secure SDLC and CI/CD environments.
Solid knowledge of web and API security concepts, OWASP Top 10, and secure coding
standards.
Hands-on experience with DevOps tools such as Jenkins, GitLab, or Azure DevOps.
Excellent communication and collaboration skills to influence security adoption across
teams.
Experience using Snyk for open-source dependency management.
Exposure to container security, IaC scanning, or cloud-native security controls.
Security certifications such as CEH, OSCP, or CSSLP
Motifire Management Services Private Limited.
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
bengaluru, karnataka, india
Salary: Not disclosed
mumbai, bengaluru
15.0 - 22.5 Lacs P.A.
9.6 - 14.4 Lacs P.A.