Sr. Devsecops Security Engineer
Publication Date:
Sep 9, 2026
Ref. No:
549791
Location:
J. P. Nagar, Bengaluru, Karnat, IN
We are looking for a highly experienced Senior DevSecOps Security Engineer to lead cybersecurity testing initiatives across web applications, APIs, CI/CD pipelines, and software supply chain environments. The ideal candidate will have strong hands-on experience integrating security into the SDLC and driving secure-by-design practices across development, QA, and production environments.
Key Responsibilities
• Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs.
• Perform and review Static Application Security Testing (SAST), including detailed source code review.
• Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments.
• Design and execute fuzzing activities for applications and APIs.
• Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components.
• Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities.
• Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes.
• Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices.
• Define and implement security testing practices across the SDLC.
• Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles.
• Identify security test scenarios during sprint planning.
• Create, maintain, and automate security test cases.
• Execute and validate security test cases across Dev, UAT, and Production promotion stages.
• Review and validate remediation activities and provide risk-based recommendations.
• Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance.
Required Skills and Experience
• 5–7 years of experience in Application Security Testing, DevSecOps.
• Strong hands-on experience in web application security testing and API security testing.
• Proven experience in:
o SAST (secure code review)
o DAST
o Fuzzing
o Software Composition Analysis (SCA)
o CI/CD pipeline security testing
o Software supply chain security testing
• Strong understanding of SDLC, secure coding practices, and shift-left security.
• Experience creating and automating security test cases in agile/sprint-based environments.
• Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
• Experience working with development, DevOps, QA, and product teams.
• Strong analytical, communication, and stakeholder management skills.
Tools Knowledge
• JFrog
• SonarQube
• Burp Suite
• Nessus
• XRAY
• JIRA
• Microsoft Threat Modeling Tool
• Postman
Preferred Qualifications
• Experience with cloud platforms such as AWS, Azure, or GCP.
• Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security.
• Experience integrating security tools into CI/CD pipelines.
• Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.