DevSecOps (Security test lead) Engineer

D-techworks

Mumbai, Bengaluru

On-site

INR 2,500,000 - 4,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

D‑techworks in Mumbai seeks a Senior Application Security/DevSecOps professional to implement and maintain SAST and SCA tooling within CI/CD pipelines, analyze findings, and guide remediation with development teams.

You will reinforce secure SDLC practices, automate security checks with Jenkins, GitLab, or Azure DevOps, and train engineers on secure coding and vulnerability management.

Qualifications

  • 5-8 years of experience in Application Security or DevSecOps domain.
  • Strong understanding of SAST and SCA tools (e.g., Checkmarx, Fortify, SonarQube, Snyk).
  • Proven ability to identify, analyze, and manage false positives effectively.
  • Good understanding of Secure SDLC and CI/CD environments.
  • Solid knowledge of web and API security concepts, OWASP Top 10, and secure coding standards.

Responsibilities

  • Implement and maintain SAST and SCA tools within the CI/CD pipeline for continuous code scanning.
  • Analyze scan results, validate and triage false positives, and ensure accuracy of reported vulnerabilities.
  • Collaborate with development teams to guide and support remediation of security vulnerabilities.
  • Work with DevOps teams to automate security checks and streamline secure build and deployment processes.
  • Perform tool integrations (Snyk, SonarQube, Checkmarx, or similar) to improve visibility of the organizations security posture.
  • Provide technical guidance and training to developers on secure coding practices.
  • Participate in threat modeling, secure design discussions, and application architecture reviews.
  • Prepare and maintain documentation for processes, standards, and tool usage.

Skills

SAST/SCA Tools
CI/CD
Threat modeling
DevSecOps
Secure coding

Tools

Jenkins
GitLab
Azure DevOps
Snyk
SonarQube
Checkmarx
Fortify

Job description

Key Responsibilities


  • Implement and maintain SAST and SCA tools within the CI/CD pipeline for continuous code scanning

  • Analyze scan results, validate and triage false positives, and ensure accuracy of reported vulnerabilities

  • Collaborate with development teams to guide and support remediation of securityvulnerabilities

  • Work with DevOps teams to automate security checks and streamline secure build and deployment processes

  • Perform tool integrations (Snyk, SonarQube, Checkmarx, or similar) to improve visibility of the organizations security posture

  • Provide technical guidance and training to developers on secure coding practices

  • Participate in threat modeling, secure design discussions, and application architecturereviews

  • Prepare and maintain documentation for processes, standards, and tool usage


.


Required Skills & Experience


  • 5- 8 years of experience in Application Security or DevSecOps domain.

  • Strong understanding of SAST and SCA tools (e.g., Checkmarx, Fortify, SonarQube, Snyk, or similar).

  • Proven ability to identify, analyze, and manage false positives effectively.

  • Good understanding of Secure SDLC and CI/CD environments.

  • Solid knowledge of web and API security concepts, OWASP Top 10, and secure coding standards.

  • Hands-on experience with DevOps tools such as Jenkins, GitLab, or Azure DevOps.

  • Excellent communication and collaboration skills to influence security adoption across teams.


Preferred / Nice to Have


  • Experience using Snyk for open-source dependency management.

  • Exposure to container security, IaC scanning, or cloud-native security controls. Security certifications such as CEH, OSCP, or CSSLP.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Rwindia • Bengaluru

On-site
INR 3,500,000 - 6,000,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
Lead SAST
Lead SAST

Daimler Trucks Innovation Center • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
DevSecOps Engineer
DevSecOps Engineer

Clinikally (YC S22) • Gurugram District

On-site
INR 800,000 - 1,400,000
Devsecops Engineer
Devsecops Engineer

Mphasis • Chennai District, Pune District

On-site
INR 2,000,000 - 3,600,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

IntraEdge • Hyderabad

On-site
INR 2,000,000 - 4,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Cyber Security Engineer
Cyber Security Engineer

Vaisesika Consulting • Bengaluru

Hybrid
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

India Fan Corporation • Hyderabad

On-site
INR 1,800,000 - 2,700,000