العودة إلى الوظائف
ScovaiScovaiJobs
2coms

2coms

Application Security Engineer (SAST & DAST, DevSecOps)

Bangalore North, INفي الموقععقددوام كامل

تم النشر في 17 أغسطس 2026

تم نشر هذه الوظيفة باللغة EN

Application Support Engineer (SAST & DAST, DevSecOps)


Experience: 7-12 years

Location: Bangalore/Hyderabad/Pune

Summary

This pivotal role focuses on strengthening enterprise application security by leveraging a comprehensive suite of testing methodologies, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secrets Detection, and Dynamic Application Security Testing (DAST). The successful candidate will act as a catalyst for embedding security into the Software Development Life Cycle (SDLC), ensuring seamless integration within CI/CD workflows. By overseeing vulnerability validation, managing Software Bill of Materials (SBOM), and driving risk-based remediation strategies, this position is essential for maintaining robust security postures and delivering actionable security metrics to stakeholders.

Responsibilities

  • Execute ongoing and targeted security assessments utilizing advanced SAST, SCA, Secrets Detection, and DAST technologies.
  • Analyze security alerts to verify accuracy, filter out false positives, and assist development teams in resolving identified vulnerabilities.
  • Embed automated security scanning mechanisms directly into CI/CD pipelines to enforce strict secure development gates.
  • Oversee the creation of SBOMs, monitor open-source dependency risks, track Common Vulnerabilities and Exposures (CVEs), and generate reports on vulnerability exposure.
  • Monitor and manage remediation Service Level Agreements (SLAs), Turnaround Time (TTD), and Time to Remediate (TTR) metrics alongside key application security performance indicators.
  • Collaborate closely with development, DevSecOps, and platform engineering units to facilitate effective remediation and foster a culture of continuous security enhancement.
  • Contribute to security evaluation efforts, optimize scanning tools, produce executive reports, and lead initiatives to empower developers with security best practices.

Requirements

  • Possess between 2-6 years of professional experience within Application Security, Secure SDLC frameworks, or DevSecOps environments.
  • Demonstrate practical expertise in managing enterprise-level AppSec scanning platforms and executing vulnerability management lifecycles.
  • Show proven ability to integrate security testing protocols into CI/CD pipelines and cloud-native infrastructure.
  • Maintain a deep understanding of the OWASP Top 10, secure coding standards, and the principles of software supply chain security.

Technical Skills & Tool Experience

  • SAST: Proficiency with Checkmarx, Veracode, Fortify, SonarQube, or GitHub Advanced Security.
  • SCA & SBOM: Experience utilizing Fortify, Checkmarx, Snyk, or Black Duck for dependency analysis.
  • DAST & API Security: Hands-on knowledge of Fortify, Checkmarx, Burp Suite, Invicti, or Acunetix.
  • Secrets Detection: Familiarity with GitGuardian or GitHub Secret Scanning capabilities.
  • DevSecOps: Competence in Azure DevOps, GitHub Actions, Jenkins, or GitLab CI/CD.
  • Container & Cloud Security: Knowledge of Prisma Cloud, Wiz, Aqua, or Microsoft Defender for Cloud.
  • Reporting & ITSM: Skills in ServiceNow, Power BI, and Grafana for data visualization and ticket management.


ملخص الدور

نوع الوظيفة

دوام كامل

المهارات المطلوبة

Static Application Security Testing (SAST)Dynamic Application Security Testing (DAST) & API SecuritySoftware Composition Analysis (SCA) and SBOM managementSecrets Detection (e.g., GitGuardian, GitHub Secret Scanning)CI/CD integration for security (DevSecOps; Azure DevOps, GitHub Actions, Jenkins, GitLab CI/CD)Vulnerability management and triage (including false positive analysis and remediation lifecycle)OWASP Top 10 knowledge and secure coding standardsCloud and container security (Prisma Cloud, Wiz, Aqua, Microsoft Defender for Cloud)Security metrics, SLA monitoring and reporting (TTD, TTR, SLAs; Power BI, Grafana)Security scanning tool evaluation and optimizationSAST tool proficiency (Checkmarx, Veracode, Fortify, SonarQube, GitHub Advanced Security)DAST and API security tools proficiency (Burp Suite, Invicti, Acunetix)

وظائف مشابهة

GC

Creative Artist

Garden City Games India Pvt Ltd

Bangalore North, INفي الموقععقددوام كامل
قبل 58 دقيقة
CI

SAP MM Consultant

Clovio IT Consulting P Ltd

Bangalore North, INفي الموقععقددوام كامل
قبل 5 ساعات
PE

Senior Mechanical Engineer – Static Equipment

Padink Engineering

Bangalore North, INفي الموقععقددوام كامل
أول أمس
PE

Civil & Structural Designer

Padink Engineering

Bangalore North, INفي الموقععقددوام كامل
أول أمس
PE

Senior Design/Site Engineer-Electrica

Padink Engineering

Bangalore North, INفي الموقععقددوام كامل
أول أمس
PE

Sr. Engineer – Civil

Padink Engineering

Bangalore North, INفي الموقععقددوام كامل
أول أمس
Application Security Engineer (SAST & DAST, DevSecOps) في 2coms في Bangalore North | Scovai | Scovai