Posted on: 27/06/2026
Key Responsibilities :
- Design and implement DevSecOps security practices across CI/CD pipelines.
- Perform application security assessments using SAST, DAST, and other security testing tools.
- Integrate automated security scans into the software development lifecycle.
- Ensure compliance with security frameworks, regulatory standards, and organizational policies.
- Identify, assess, and remediate application and cloud security vulnerabilities.
- Collaborate with development, DevOps, and cloud engineering teams to implement secure coding practices.
- Develop and enforce cloud security controls across AWS, Azure, or GCP environments.
- Conduct threat modeling, risk assessments, and security reviews for applications and cloud infrastructure.
- Monitor security posture, investigate incidents, and recommend remediation measures.
- Stay updated with emerging security threats, tools, and DevSecOps best practices.
Required Technical Skills :
- Strong experience in Application Security.
- Hands-on experience with SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) tools.
- Knowledge of cloud security principles and best practices (AWS, Azure, or GCP).
- Experience with DevSecOps practices and CI/CD security integration.
- Strong understanding of security compliance frameworks such as ISO 27001, SOC 2, PCI-DSS, CIS, or NIST.
- Expertise in vulnerability management, threat modeling, and security risk assessment.
- Experience with IAM (Identity and Access Management), secrets management, and security monitoring.
- Knowledge of container security (Docker, Kubernetes) and Infrastructure as Code (Terraform/CloudFormation) is preferred.
- Familiarity with scripting languages such as Python, Bash, or PowerShell is an advantage.
Preferred Skills :
- Cloud Security (AWS Security, Azure Security, or GCP Security)
- DevSecOps & Secure CI/CD Pipelines
- SAST & DAST Tools (Checkmarx, Veracode, Fortify, SonarQube, Burp Suite, OWASP ZAP, etc.)
- Vulnerability Assessment & Penetration Testing (VAPT)
- Security Compliance & Governance
- Secure SDLC
- IAM & Secrets Management
- Container & Kubernetes Security
- Threat Modeling & Risk Assessment
- Excellent analytical, communication, and stakeholder management skills.
Did you find something suspicious?
Posted by
Satakhsi Chakrabarty
Staffing Analyst (IT Recruiter) at Black & White Business Solutions
Last Active: 27 Jun 2026
Posted in
DevOps / SRE
Functional Area
DevOps / Cloud
Job Code
1649111