Sr. Devsecops Security Engineer

Publication Date:  Sep 9, 2026
Ref. No:  549791
Location: 

J. P. Nagar, Bengaluru, Karnat, IN

We are looking for a highly experienced Senior DevSecOps Security Engineer to lead cybersecurity testing initiatives across web applications, APIs, CI/CD pipelines, and software supply chain environments. The ideal candidate will have strong hands-on experience integrating security into the SDLC and driving secure-by-design practices across development, QA, and production environments. Key Responsibilities • Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs. • Perform and review Static Application Security Testing (SAST), including detailed source code review. • Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments. • Design and execute fuzzing activities for applications and APIs. • Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components. • Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities. • Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes. • Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices. • Define and implement security testing practices across the SDLC. • Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles. • Identify security test scenarios during sprint planning. • Create, maintain, and automate security test cases. • Execute and validate security test cases across Dev, UAT, and Production promotion stages. • Review and validate remediation activities and provide risk-based recommendations. • Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance. Required Skills and Experience • 5–7 years of experience in Application Security Testing, DevSecOps. • Strong hands-on experience in web application security testing and API security testing. • Proven experience in: o SAST (secure code review) o DAST o Fuzzing o Software Composition Analysis (SCA) o CI/CD pipeline security testing o Software supply chain security testing • Strong understanding of SDLC, secure coding practices, and shift-left security. • Experience creating and automating security test cases in agile/sprint-based environments. • Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities. • Experience working with development, DevOps, QA, and product teams. • Strong analytical, communication, and stakeholder management skills. Tools Knowledge • JFrog • SonarQube • Burp Suite • Nessus • XRAY • JIRA • Microsoft Threat Modeling Tool • Postman Preferred Qualifications • Experience with cloud platforms such as AWS, Azure, or GCP. • Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security. • Experience integrating security tools into CI/CD pipelines. • Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.