Experience : 5- 10 years
Work Location : Bangalore
Job Title : SAST / DevSecOps Security Engineer
Job Summary :
We are seeking an experienced SAST / DevSecOps Security Engineer with strong programming skills and deep expertise in Static Application Security Testing (SAST) tools such as Fortify and Checkmarx. The role focuses on secure-by-design enablement, CI/CD integration, false-positive triaging, and hands-on remediation guidance for development teams. The ideal candidate will work closely with developers, DevOps, and architecture teams to embed security into the SDLC, reduce noise from automated scans, and drive meaningful vulnerability remediation.
Primary Tools & Technologies :
- Fortify (SSC, ScanCentral, SCA)
- Checkmarx
- CI/CD : Jenkins, GitHub Actions, Azure DevOps
- Languages (strong hands-on required in at least one) :
1. Java
2. Python
3. JavaScript / TypeScript
4. C# / .NET
- Build tools : Maven, Gradle, npm, MSBuild
- SCM : Git (GitHub, GitLab, Bitbucket)
Required Skills & Qualifications :
- 5 to 10 years of experience in Application Security / SAST / DevSecOps
- Strong programming background with ability to :
1. Read, understand, and debug production code
2. Trace data flow and execution paths
- Deep hands-on expertise in Fortify and/or Checkmarx
- Strong understanding of :
1. OWASP Top 10
2. CWE / CVE
3. Secure coding principles
- Experience working in enterprise, CI/CD-driven environments
Good to Have :
- Experience with SCA tools (Mend, Black Duck, Snyk)
- API and microservices security exposure
- Infrastructure-as-Code scanning exposure
- Certifications :
1. CSSLP
2. GWAPT
3. Secure Code Warrior
4. Fortify / Checkmarx certifications
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1651101