Collaborate with engineering, operations, and security teams to design, implement, automate and maintain an effective application security program
Implement, triage security vulnerabilities and automate security controls like SAST, DAST, SCA and IaC
Analyze security vulnerabilities pertaining to DevOps platforms like GitHub Action, Drone, Jenkins, Spinnaker
Develop the security best practices, standards and guidelines for engineering teams across different technologies and provide support in implementing them
Develop security controls and process to be implemented as self-service and work with different stakeholders for implementation
Develop and automate day-to-day operational tasks and deployment methods
Support red team in performing security assessment of, but not limited to, web & mobile application, containers, k8s, thick client, cloud environments
Qualifications/Requirements
6+ years experience in application security and DevSecOps domain in product based organization
Proven experience in security engineering and DevSecOps functions, building and managing security solutions across the stack
Understanding of overall software development process and implementation of security controls in CICD pipeline
Understanding of DevOps controls, process & technologies and security vulnerabilities pertaining to them
Expertise in automating complex day-to-day operational tasks using Python or any other scripting language
Knowledge of OWASP Web and Mobile Top 10 vulnerabilities, identifying, exploiting and remediating them
Excellent written and verbal communication skills.
Self-motivated, curious, knowledgeable pertaining to news and current events