Search by job, company or skills

Senior DevSecOps / Vulnerability Remediation Engineer

Senior DevSecOps / Vulnerability Remediation Engineer

scubyt inc
Fresher
Not Disclosed
Early Applicant
  • Posted a month ago
  • Be among the first 10 applicants

Job Description

Title: Senior DevSecOps / Vulnerability Remediation Engineer

Location: India (REMOTE)

Eastern Time Zone (6.30 PM IST to 3.30 AM IST)

Long Term Contract

Position Overview

We are seeking a hands-on *Senior DevSecOps / Vulnerability Remediation Engineer* to own application security vulnerabilities from initial identification through production deployment.

This role requires a strong combination of *software engineering, application security, DevOps, and SRE experience. The engineer will work across legacy **Java, Python, and JavaScript applications*, analyze vulnerabilities identified by security tooling, determine the appropriate remediation, implement code and dependency fixes, resolve resulting build issues, update deployment pipelines, and successfully deploy the remediation into production.

This is primarily a *security remediation role rather than feature development*.

Key Responsibilities

* Own application vulnerabilities from *initial identification through production remediation and verification*.

* Triage CVEs and security findings across Java, Python, and JavaScript applications.

* Perform hands-on code changes to remediate identified vulnerabilities.

* Upgrade vulnerable libraries, frameworks, and application dependencies.

* Troubleshoot application or build failures caused by dependency upgrades.

* Work within legacy codebases developed by other engineering teams.

* Update and maintain CI/CD and release pipelines required to deploy security fixes.

* Manage artifact versioning, promotion, and release processes.

* Validate successful remediation after deployment and ensure vulnerabilities are properly closed.

* Work across multiple applications and technology stacks as remediation priorities change.

Required Skills

* Strong hands-on software development experience with *Java, Python, and JavaScript*.

* Demonstrated experience performing *application vulnerability and CVE remediation*.

* Proven experience taking security findings through the complete lifecycle: *triage → code/dependency remediation → build → deployment → verification*.

* Strong experience with legacy application dependency upgrades and troubleshooting resulting compatibility or build issues.

* Strong CI/CD and release engineering experience.

* Hands-on experience with technologies such as:

Jenkins

GitLab

Harness

Artifactory

ArgoCD

* Experience managing artifact libraries, including *versioning and promotion between environments*.

* Ability to work independently across unfamiliar legacy applications and quickly identify remediation approaches.

Highly Preferred

* Experience using *Harness and ArgoCD/GitOps together*.

* Strong examples of resolving failed builds or application issues resulting from security-driven dependency upgrades.

* Experience switching between *Java, Python, and JavaScript applications* within the same environment.

* Strong understanding of secure software development and DevSecOps practices.

Success in This Role

Success will be measured by consistently reducing the vulnerability backlog and taking each assigned security issue completely from identification through *remediation, testing, pipeline integration, production deployment, and verification*.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

About Company