Application Security Engineer (SAST & DAST, DevSecOps)
2comsCahmrajendrapet, Bangalore
it-jobs
Job Description
Application Support Engineer (SAST & DAST, DevSecOps) Experience: 7-12 years Location: Bangalore/Hyderabad/Pune Summary This pivotal role focuses on strengthening enterprise application security by leveraging a comprehensive suite of testing methodologies, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secrets Detection, and Dynamic Application Security Testing (DAST). The successful candidate will act as a catalyst for embedding security into the Software Development Life Cycle (SDLC), ensuring seamless integration within CI/CD workflows. By overseeing vulnerability validation, managing Software Bill of Materials (SBOM), and driving risk-based remediation strategies, this position is essential for maintaining robust security postures and delivering actionable security metrics to stakeholders. Responsibilities - Execute ongoing and targeted security assessments utilizing advanced SAST, SCA, Secrets Detection, and DAST technologies. - Analyze security alerts to verify accuracy, filter out false positives, and assist development teams in resolving identified vulnerabilities. - Embed automated security scanning mechanisms directly into CI/CD pipelines to enforce strict secure development gates. - Oversee the creation of SBOMs, monitor open-source dependency risks, track Common Vulnerabilities and Exposures (CVEs), and generate reports on vulnerability exposure. - Monitor and manage remediation Service Level Agreements (SLAs), Turnaround Time (TTD), and Time to Remediate (TTR) metrics alongside key application security performance indicators. - Collaborate closely with development, DevSecOps, and platform engineering units to facilitate effective remediation and foster a culture of continuous security enhancement. - Contribute to security evaluation efforts, optimize scanning tools, produce executive reports, and lead initiatives to empower developers with security best practices. Requirements - Possess between 2-6 years of professional experience within Application Security, Secure SDLC frameworks, or DevSecOps environments. - Demonstrate practical expertise in managing enterprise-level AppSec scanning platforms and executing vulnerability management lifecycles. - Show proven ability to integrate security testing protocols into CI/CD pipelines and cloud-native infrastructure. - Maintain a deep understanding of the OWASP Top 10, secure coding standards, and the principles of software supply chain security. Technical Skills & Tool Experience - SAST: Proficiency with Checkmarx, Veracode, Fortify, SonarQube, or GitHub Advanced Security. - SCA & SBOM: Experience utilizing Fortify, Checkmarx, Snyk, or Black Duck for dependency analysis. - DAST & API Security: Hands-on knowledge of Fortify, Checkmarx, Burp Suite, Invicti, or Acunetix. - Secrets Detection: Familiarity with GitGuardian or GitHub Secret Scanning capabilities. - DevSecOps: Competence in Azure DevOps, GitHub Actions, Jenkins, or GitLab CI/CD. - Container & Cloud Security: Knowledge of Prisma Cloud, Wiz, Aqua, or Microsoft Defender for Cloud. - Reporting & ITSM: Skills in ServiceNow, Power BI, and Grafana for data visualization and ticket management.
Get AI-Matched to This Job
Upload your resume and our AI will score how well you match this and thousands of similar roles.