DevSecOps SME - Contract

NCS Group

City of Melbourne

Hybrid

AUD 150,000 - 185,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NCS Australia is seeking a hands-on DevScope SME / Senior DevSecOps Engineer to drive security scanning standards across enterprise pipelines. You will own the design, implementation and rollout of SAST, SCA and DAST platforms, embedding checks directly into CI/CD workflows and defining false-positive triage strategies.

Based in Sydney with hybrid work options, you will collaborate with software engineering squads to enable secure coding, establish security gates, and automate reporting across

Qualifications

  • Proven implementation track record deploying enterprise SAST, SCA and DAST tooling.
  • DevSecOps automation in automated CI/CD pipelines and developer tools.
  • Deep understanding of OWASP Top 10, CWE, OSS risk and dependency vulnerability management.
  • Scripting in Python, Bash or PowerShell with API integrations.
  • Location: Based in Sydney with Australian working rights and hybrid work in Sydney.

Responsibilities

  • Platform implementation and rollout of code scanning platforms across enterprise repositories.
  • Governance for SAST, SCA & DAST including baseline rulesets and enforcement.
  • Embed security testing stages and quality gates into CI/CD pipelines (GitLab CI, GitHub Actions, Azure DevOps, Jenkins).
  • Define Dev Scope and triage strategy to minimize friction while maintaining security coverage.
  • Enable engineers with secure coding standards and developer-first security practices.

Skills

DevSecOps
CI/CD
Scripting
Vulnerability
OWASP Top 10

Tools

Checkmarx
SonarQube
Veracode
Snyk
Fortify
OWASP ZAP
GitLab CI
GitHub Actions
Azure DevOps
Jenkins

Job description

Company Description

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

Job Description

We are seeking a hands-on DevScope SME / Senior DevSecOps Engineer to drive the end-to-end design, implementation, and roll-out of application security scanning standards across enterprise engineering pipelines.

This is not an operational or monitoring position—it is a delivery-focused engineering role for a specialist who has built, integrated, and deployed SAST, SCA, and DAST platforms from the ground up. You will take ownership of defining security scanning boundaries (Dev Scope), establishing quality gates, configuring scanning engines, and automating security controls directly within active CI/CD pipelines.

Key Responsibilities
  • Platform Implementation & Roll‑Out: Lead the end-to-end configuration, deployment, and integration of code scanning platforms (e.g., Checkmarx, SonarQube, Veracode, Snyk, Fortify, or OWASP ZAP) across enterprise repositories.

  • SAST, SCA & DAST Governance: Establish baseline rulesets, policy standards, and enforcement mechanisms for Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST).

  • Pipeline Security Automation: Embed automated security testing stages, quality gates, and failure conditions seamlessly into modern CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Azure DevOps, Jenkins).

  • Dev Scope & Triage Strategy: Define the operational scope of security scanning, establish false‑positive triage workflows, and optimize rulesets to minimize developer friction while maintaining high security coverage.

  • Engineering Enablement: Work directly with software engineering squads to provide guided remediation, establish secure coding standards, and build developer‑first security

Qualifications

Essential Experience:

  • Proven Implementation Track Record: Demonstrated experience building, configuring, and deploying enterprise SAST, SCA, and DAST tooling (not just using or monitoring existing configurations).

  • DevSecOps Automation: Strong hands‑on experience integrating application security testing directly into automated CI/CD pipelines and developer tools.

  • AppSec & Vulnerability Management: Deep understanding of the OWASP Top 10, CWE, open‑source license risk, and dependency vulnerability management.

  • Scripting & Integration: Proficiency in scripting (Python, Bash, or PowerShell) and working with APIs to automate scanning workflows and reporting.

  • Location: Based in Sydney (or willing to work hybrid in Sydney) with full Australian working rights.

Additional Information
Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Group • Sydney

Hybrid
AUD 150,000 - 210,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Australia • City of Melbourne

Hybrid
AUD 120,000 - 180,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Group Australia • Sydney

Hybrid
AUD 150,000 - 210,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS • City of Melbourne

Hybrid
AUD 150,000 - 190,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Australia • Sydney

On-site
AUD 140,000 - 200,000
Lead DevSecOps & AI Security Specialist - Contract
Lead DevSecOps & AI Security Specialist - Contract

NCS • Sydney

Hybrid
AUD 180,000 - 240,000
Technical Business Analyst (DevSecOps) - Contract
Technical Business Analyst (DevSecOps) - Contract

NCS Group Australia • Sydney

On-site
AUD 120,000 - 180,000
Technical Business Analyst (DevSecOps) - Contract
Technical Business Analyst (DevSecOps) - Contract

NCS • Sydney

On-site
AUD 110,000 - 140,000
Technical Business Analyst (DevSecOps) - Contract
Technical Business Analyst (DevSecOps) - Contract

NCS Australia • Sydney

On-site
AUD 140,000 - 190,000
Senior DevSecOps Engineer — Secure CI/CD Architect
Senior DevSecOps Engineer — Secure CI/CD Architect

NCS Group Australia • Sydney

Hybrid
AUD 150,000 - 210,000