HamburgerMenu
hirist

DevSecOps/Application Security Engineer

SysMind
4 - 6 Years
Hyderabad

Posted on: 10/08/2026

Job Description

Job Description DevSecOps / Application Security Engineer

Role : DevSecOps Engineer CodeQL / Coverity / GitHub Actions

Experience : 46 Years

Role Overview :

We are looking for an experienced DevSecOps / Application Security Engineer with strong expertise in GitHub Actions, CodeQL, Coverity, C/C++ development, and secure CI/CD practices.


The candidate will be responsible for building and optimizing CI pipelines, integrating security and code-quality scanning into the software development lifecycle, troubleshooting scanning and pipeline issues, and helping engineering teams adopt effective shift-left security practices.

Key Responsibilities :

- Design, develop, maintain, and enhance GitHub Actions CI/CD pipelines for C/C++ and Java applications.

- Integrate and manage CodeQL and Coverity security/static-analysis scans within pull-request and scheduled CI workflows.

- Configure and optimize security scanning rules to improve detection accuracy and minimize false positives.

- Develop custom CodeQL queries and Coverity rules where required.

- Automate security finding triage, reporting, remediation tracking, PR checks, dashboards, and ticketing workflows.

- Manage CI scan infrastructure, including runners, containers, and cloud-based environments.

- Secure and manage CI/CD secrets and credentials according to security best practices.

- Improve pipeline execution time through optimization, caching, parallel execution, and other CI efficiency techniques.

- Investigate and resolve CI/CD pipeline failures, compiler issues, and static-analysis tool failures.

- Work closely with development, security, DevOps, and platform engineering teams to resolve security findings and improve code quality.

- Promote shift-left security by integrating security checks earlier in the development lifecycle.

- Prepare technical documentation, onboarding guides, operational procedures, and knowledge-sharing material.

- Support the transition of stable CI/security processes to the platform engineering team.

- Contribute to organization-wide application security and software quality improvement initiatives.

Mandatory Technical Skills :

- Strong hands-on C/C++ development and debugging, particularly modern C++.

- Production experience with CodeQL mandatory.

- Hands-on experience with Coverity is highly desirable.

- Strong experience with GitHub Actions or equivalent CI/CD automation platforms.

- Familiarity with GitHub Advanced Security (GHAS).

- Strong scripting skills using Bash and/or Python.

- Experience with Docker.

- Working knowledge of Kubernetes.

- Basic knowledge of cloud platforms.

- Experience troubleshooting CI/CD and static-analysis failures.

- Understanding of secure software development and shift-left security practices.

Preferred / Nice-to-Have Skills :

- Development of custom CodeQL queries.

- Creation or customization of Coverity rules.

- Enterprise-scale CI/CD optimization.

- Build caching and distributed build environments.

- Experience with observability, monitoring, and engineering metrics.

- Knowledge of build systems such as :

1. Gradle

2. Make

3. CMake

4. Bazel

5. NMake

- Familiarity with development tools and compilers such as :

1. GCC

2. Protoc

3. Microsoft Visual Studio / CL

Key Functional Areas :

- DevSecOps | Application Security | CI/CD Automation | Static Code Analysis | Secure SDLC | Shift-Left Security

Primary Tools & Technologies :

- GitHub Actions | CodeQL | Coverity | GHAS | C/C++ | Java | Bash | Python | Docker | Kubernetes | Cloud | CI/CD

Soft Skills :

- Strong analytical and troubleshooting capabilities.

- Effective communication with development, security, and platform teams.

- Ability to drive remediation activities across multiple engineering teams.

- Self-motivated and capable of independently owning security and quality initiatives.

- Ability to work with technical and leadership stakeholders to implement organization-wide improvements.

- Strong documentation and knowledge-sharing skills.

Experience :

- 4 to 6 years of relevant experience in DevSecOps, Application Security, CI/CD Engineering, or Software Security Engineering.

Essential Skills :

- CodeQL, GitHub Actions, C/C++ Debugging, DevSecOps, CI/CD, Static Application Security Testing (SAST)

Desirable Skills :

- Coverity, GHAS, Docker, Kubernetes, Python/Bash, Cloud, Custom CodeQL Queries, CI Optimization

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...