DevSecOps & Application Security Engineer
Role Summary:
Experienced security practitioner focused on DevSecOps, application security, and cloud security architecture, supporting a banking/financial services client’s secure SDLC, infrastructure-as-code, supply-chain security, and privileged access / PKI controls.
Key Responsibilities:
- Design, develop, and review Terraform (IaC) with a security-first approach; perform IaC code reviews
- Architect and implement deep technical security controls across AWS and Microsoft (Azure / Microsoft security) environments
- Embed application security practices across design and delivery
- Implement policy-as-code enforcement across the SDLC — PR-time, pipeline-time, deploy-time, and runtime
- Drive supply-chain security: signed builds (Sigstore/cosign), SBOM generation, SLSA-aligned provenance, dependency pinning, runner isolation
- Set up and operationalize Veracode and/or GitHub Advanced Security
- Deploy and support CyberArk PAM and PKI
- Contribute to security runbooks, pipeline standards, and process documentation
- Support audit and compliance evidence gathering
- Escalate and coordinate on critical security events with senior leadership
Required Experience:
- 7+ years in cybersecurity operations/engineering, cloud security, or DevSecOps
- Hands-on Terraform coding and IaC code review experience
- Deep technical AWS and Microsoft security and architecture experience
- Application security experience
- History of setting up Veracode and/or GitHub Advanced Security
- CyberArk PAM and PKI deployment experience
- BFSI or other regulated-industry experience preferred
Core Technical Expertise:
- Terraform / infrastructure-as-code security and code review
- AWS security architecture; Microsoft Azure / Microsoft security architecture
- DevSecOps toolchains and secure SDLC integration
- Application security (SAST/DAST/SCA in practice)
- Policy-as-code across PR, pipeline, deploy, and runtime
- Supply-chain security: Sigstore/cosign, SBOM, SLSA-aligned provenance, dependency pinning, runner isolation
- CyberArk PAM (deployment); PKI (deployment)
- Veracode and/or GitHub Advanced Security
Preferred Certifications:
- AWS Certified Security – Specialty; Microsoft security/architecture certifications (e.g., AZ-500, SC-100, or equivalent) as applicable