
Search by job, company or skills
Experience with performing manual and automated SAST assessments.
Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.) updated and familiarized with the latest exploits and security trends.
Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, HCL AppScan, BurpSuite)
Familiarity with static code analysis tools and services (CheckMarx, Snyk, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source)
Experience in developing a DevSecOps CI/CD pipeline completely using open source tools.
Experience with SCM tools like Github, Gitlab, Bitbucket and their ability to integrated with CI/CD pipelines by using webhooks, actions, etc.
Experience with implementing different phases of CI/CD like secret scanning, SAST, SCA, DAST, Infrastructure as code, compliance as code, vulnerability management.
Optimizing the pipeline to produce the best results and ability to plan a maturity model for the DevSecOps program.
Understanding of web-based application vulnerabilities (OWASP Top 10).
Experience with scripting / programming skills (e.g., Python or PowerShell or Java or Perl etc.).
To qualify for the role, you must have
BE/ B.Tech/ MCA.
Minimum of 3 years of full-time work experience in SAST, SCA, DAST and DevSecOps.
Knowledge of Windows, Linux, UNIX, any other major operating systems.
Strong Excel and PowerPoint skills.
Ideally, you will also have
Familiarity with programming languages such as Java, JavaScript, Python and Angular
Strong knowledge of relevant Security Standards (OWASP) and how to apply them to the software development lifecycle in a large agile environment.
Experience performing security analysis on web applications and APIs.
Experience working in an Agile environment.
Job ID: 147373893
Skills:
Angular, Java, Zookeeper, Soap, Maven, Junit, Aop, Agile Methodologies, Kafka, Eclipse, Spring MVC, Api, Confluence, Design Patterns, Git, Intellij, Spring Boot, Jbehave, Ant, Rally, Gradle, Json, Hibernate, Mockito, Ioc, Jenkins, Web-services, Security, My Eclipse IDE
We don’t charge any money for job offers