DevSecOps Engineer (SAST/DAST)

Zohorecruit

Hyderabad

On-site

INR 2,000,000 - 3,500,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Security architecture reviews
Threat modeling exercises
Threat model to test cases

Job summary

Algoleap Technologies Pvt Ltd in Hyderabad is seeking a Consultant to serve as a SAST/DAST professional, integrating security testing into CI/CD pipelines and performing regular assessments.

You will triage results, provide remediation guidance to development teams, and collaborate with stakeholders to enforce SSDLC and OWASP Top 10 compliance.

Experience with Checkmarx, Veracode, Fortify, Burp Suite, and OWASP ZAP is desirable, along with relevant certifications.

Qualifications

  • Bachelor's degree or higher in Computer Science, or equivalent experience.
  • Security certifications such as CSSLP, CEH, or similar.
  • Experience with cloud-native application security and container security.
  • Knowledge of regulatory and compliance requirements related to application security.

Responsibilities

  • Integrate SAST and DAST tools into CI/CD pipelines to automate security testing throughout the development lifecycle.
  • Perform regular static (SAST) and dynamic (DAST) security assessments on applications to identify vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.
  • Analyze scan results, triage findings, and provide actionable remediation guidance to development teams.
  • Collaborate with developers to ensure secure coding practices and support secure design reviews.
  • Define and maintain security roles, responsibilities, and ownership between Deloitte and client stakeholders for test preparation, execution, and support.
  • Ensure that vulnerabilities are tracked, reported, and resolved in accordance with organizational policies and client requirements.
  • Conduct root cause analysis (RCA) workshops and publish performance and security testing reports.
  • Stay current with industry trends, emerging threats, and advancements in SAST/DAST tools and methodologies.

Skills

SAST tools
DAST tools
CI/CD integration
Vulnerability assessment
OWASP Top 10
SSDLC
Stakeholder communication
Black-box testing
White-box testing

Education

Bachelor's degree in CS
CSSLP / CEH or similar
Security certifications

Tools

Checkmarx
Veracode
Fortify
Burp Suite
OWASP ZAP

Job description

Algoleap Technologies Pvt Ltd | Full time

As a Consultant, you are responsible for performing following activities as a SAST/DAST professional:

· Integrate SAST and DAST tools into CI/CD pipelines to automate security testing throughout the development lifecycle.

· Perform regular static (SAST) and dynamic (DAST) security assessments on applications to identify vulnerabilities such as SQL injection, cross-site scripting,and other OWASP Top 10 risks.

· Analyze scan results, triage findings, and provide actionable remediation guidance to development teams.

· Collaborate with developers to ensure secure coding practices and support secure design reviews.

· Define and maintain security roles, responsibilities, and ownership between Deloitte and client stakeholders for test preparation, execution, and support.

· Ensure that vulnerabilities are tracked, reported, and resolved in accordance with organizational policies and client requirements.

· Conduct root cause analysis (RCA) workshops and publish performance and security testing reports.

· Stay current with industry trends, emerging threats, and advancements in SAST/DAST tools and methodologies.

Required skills
  • Hands-on experience with leading SAST and DAST tools (e.g., Checkmarx, Veracode, Fortify, Burp Suite, OWASP ZAP)
  • Strong understanding of secure software development lifecycle (SSDLC) principles and OWASP Top 10 vulnerabilities
  • Experience integrating security testing into CI/CD pipelines (e.g., Jenkins, Azure DevOps, GitLab CI)
  • Ability to interpret and communicate vulnerability findings and remediation steps to technical and non-technical stakeholders
  • Familiarity with both black-box (DAST) and white-box (SAST) testing methodologies
Qualification

· Bachelor's degree or higher in Computer Science, or equivalent experience.

· Security certifications such as CSSLP, CEH, or similar.

· Experience with cloud-native application security and container security.

· Knowledge of regulatory and compliance requirements related to application security.

Good to have:
  • Experience participating in or conducting security architecture reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards
  • Proficiency in performing threat modeling exercises (e.g., using STRIDE, PASTA, or other frameworks) to systematically identify, document, and prioritize potential threats and attack vectors in applications and systems
  • Skill in translating threat model findings into actionable SAST/DAST test cases and ensuring that identified threats are adequately tested and mitigated
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs
DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs

Alignity • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Equal Opportunity Employer
DevSecOps Engineer (SAST/DAST)
DevSecOps Engineer (SAST/DAST)

AlgoLeap Technologies Pvt Ltd. • Hyderabad

On-site
INR 1,200,000 - 1,800,000
SAST/DAST Application Security Consultant (Pen Testing)
SAST/DAST Application Security Consultant (Pen Testing)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Testing Consultant with SAST and DAST
Application Security Testing Consultant with SAST and DAST

Cloudxtreme • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Security Consultant (SAST & DAST)
Application Security Consultant (SAST & DAST)

Alignity • Hyderabad

Hybrid
INR 1,500,000 - 2,500,000
Sr. Devsecops Security Engineer
Sr. Devsecops Security Engineer

Atos SE • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Security/SAST/DAST/SCA
Security/SAST/DAST/SCA

Heptarc • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Application Security Engineer (SAST / DAST / DevSecOps / SCA)
Application Security Engineer (SAST / DAST / DevSecOps / SCA)

Qualizeal India • Hyderabad

On-site
INR 1,200,000 - 1,800,000