Posted on: 10/08/2026
Job Description DevSecOps / Application Security Engineer
Role : DevSecOps Engineer CodeQL / Coverity / GitHub Actions
Experience : 46 Years
Role Overview :
We are looking for an experienced DevSecOps / Application Security Engineer with strong expertise in GitHub Actions, CodeQL, Coverity, C/C++ development, and secure CI/CD practices.
The candidate will be responsible for building and optimizing CI pipelines, integrating security and code-quality scanning into the software development lifecycle, troubleshooting scanning and pipeline issues, and helping engineering teams adopt effective shift-left security practices.
Key Responsibilities :
- Design, develop, maintain, and enhance GitHub Actions CI/CD pipelines for C/C++ and Java applications.
- Integrate and manage CodeQL and Coverity security/static-analysis scans within pull-request and scheduled CI workflows.
- Configure and optimize security scanning rules to improve detection accuracy and minimize false positives.
- Develop custom CodeQL queries and Coverity rules where required.
- Automate security finding triage, reporting, remediation tracking, PR checks, dashboards, and ticketing workflows.
- Manage CI scan infrastructure, including runners, containers, and cloud-based environments.
- Secure and manage CI/CD secrets and credentials according to security best practices.
- Improve pipeline execution time through optimization, caching, parallel execution, and other CI efficiency techniques.
- Investigate and resolve CI/CD pipeline failures, compiler issues, and static-analysis tool failures.
- Work closely with development, security, DevOps, and platform engineering teams to resolve security findings and improve code quality.
- Promote shift-left security by integrating security checks earlier in the development lifecycle.
- Prepare technical documentation, onboarding guides, operational procedures, and knowledge-sharing material.
- Support the transition of stable CI/security processes to the platform engineering team.
- Contribute to organization-wide application security and software quality improvement initiatives.
Mandatory Technical Skills :
- Strong hands-on C/C++ development and debugging, particularly modern C++.
- Production experience with CodeQL mandatory.
- Hands-on experience with Coverity is highly desirable.
- Strong experience with GitHub Actions or equivalent CI/CD automation platforms.
- Familiarity with GitHub Advanced Security (GHAS).
- Strong scripting skills using Bash and/or Python.
- Experience with Docker.
- Working knowledge of Kubernetes.
- Basic knowledge of cloud platforms.
- Experience troubleshooting CI/CD and static-analysis failures.
- Understanding of secure software development and shift-left security practices.
Preferred / Nice-to-Have Skills :
- Development of custom CodeQL queries.
- Creation or customization of Coverity rules.
- Enterprise-scale CI/CD optimization.
- Build caching and distributed build environments.
- Experience with observability, monitoring, and engineering metrics.
- Knowledge of build systems such as :
1. Gradle
2. Make
3. CMake
4. Bazel
5. NMake
- Familiarity with development tools and compilers such as :
1. GCC
2. Protoc
3. Microsoft Visual Studio / CL
Key Functional Areas :
- DevSecOps | Application Security | CI/CD Automation | Static Code Analysis | Secure SDLC | Shift-Left Security
Primary Tools & Technologies :
- GitHub Actions | CodeQL | Coverity | GHAS | C/C++ | Java | Bash | Python | Docker | Kubernetes | Cloud | CI/CD
Soft Skills :
- Strong analytical and troubleshooting capabilities.
- Effective communication with development, security, and platform teams.
- Ability to drive remediation activities across multiple engineering teams.
- Self-motivated and capable of independently owning security and quality initiatives.
- Ability to work with technical and leadership stakeholders to implement organization-wide improvements.
- Strong documentation and knowledge-sharing skills.
Experience :
- 4 to 6 years of relevant experience in DevSecOps, Application Security, CI/CD Engineering, or Software Security Engineering.
Essential Skills :
- CodeQL, GitHub Actions, C/C++ Debugging, DevSecOps, CI/CD, Static Application Security Testing (SAST)
Desirable Skills :
- Coverity, GHAS, Docker, Kubernetes, Python/Bash, Cloud, Custom CodeQL Queries, CI Optimization
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1661732