Senior DevSecOps Engineer

Thermo Fisher Scientific India Pvt Ltd

Bengaluru

On-site

INR 4,000,000 - 6,500,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Thermo Fisher Scientific India Pvt Ltd invites a Senior DevSecOps Engineer to lead security automation and tooling integration across MSD projects from Bengaluru. You will embed secure-by-default practices into software lifecycles, drive SBOM generation, secret scanning, and SAST integration within CI/CD pipelines.

You will mentor teams, shape standards, and improve documentation while ensuring scalable, repeatable security automation and governance across multiple repositories.

Qualifications

  • 8–12 years in DevSecOps or security engineering roles.
  • Strong CI/CD ownership and leadership.
  • Hands-on with security tooling in CI/CD pipelines.
  • SBOM generation/management and vulnerability workflows.
  • Secret scanning and SAST integration experience.
  • Familiar with Dependency-Track and DefectDojo.
  • Scripting skills in Python/PowerShell/Bash.
  • Ability to document complex technical topics clearly.

Responsibilities

  • Provide technical leadership for DevSecOps across MSD projects.
  • Integrate and operationalize security tooling in projects.
  • Improve SBOM quality with standards and KPIs.
  • Design CI/CD to generate security reports and publish to Dependency-Track and DefectDojo.
  • Build security-as-code patterns for broad adoption.
  • Mentor engineers to improve remediation workflows.
  • Secure credential handling in pipelines with least privilege.
  • Lead cross-functional security/DevOps/engineering groups.
  • Create and maintain runbooks, onboarding guides, and architecture docs.
  • Provide operational support for tooling integrations.

Skills

Technical leadership
CI/CD ownership
Security tooling in CI/CD
Scripting: Python
SBOM/Dependency tracking
DefectDojo & Dependency-Track familiar
Secret scanning
SAST integration
Troubleshooting
Documentation

Tools

Jenkins
GitHub Actions
GitLab CI
Dependency-Track
DefectDojo
CycloneDX/ SPDX

Job description

Senior DevSecOps Engineer Work Schedule Standard (Mon-Fri) Environmental Conditions Office Job Description Job Description We are seeking a Senior DevSecOps Engineer (8-12 years of experience) with demonstrated technical leadership experience to lead security automation and tooling integration across projects .

This role will focus on embedding security controls into the software delivery lifecycles specifically SBOM generation and quality improvement, secret scanning, and SAST integration -and automating security report generation and publishing into platforms such as Dependency-Track and DefectDojo . You will work closely with engineering, DevOps, and security stakeholders to drive adoption of secure-by-default practices, influence technical direction, and ensure scalable, repeatable, and measurable security automation through CI/CD pipelines. You will also help raise the overall maturity of the program through mentorship, standards, and continuously improving documentation.

Key Responsibilities
  • Provide technical leadership for DevSecOps initiatives across MSD projects, including driving best practices, standardization, and adoption across teams.
  • Integrate and operationalize security tooling within MSD projects, including: SBOM generation and validation Secret scanning SAST (Static Application Security Testing)
  • Improve the quantity (coverage) and quality of generated SBOMs by defining standards, validation gates, and measurable KPIs (e.g., completeness, dependency accuracy, license metadata, component version resolution).
  • Design and maintain CI/CD automation to generate security reports and automatically publish results to: Dependency-Track (SBOM ingestion / component risk analysis) DefectDojo (centralized vulnerability management / reporting)
  • Build and maintain "security as code" patterns (pipeline templates, reusable scripts, standardized configs) to enable broad adoption across multiple repositories/teams.
  • Mentor engineers and partners with development teams to improve remediation workflows by tuning rulesets, improving signal-to-noise, and ensuring findings are actionable.
  • Establish secure and scalable practices for credential handling in pipelines (least privilege, secret management patterns, rotation support).
  • Lead or contribute to cross-functional working groups with Security, DevOps, and Engineering to align on standards, prioritization, and measurable outcomes.
  • Create, maintain, and continuously improve documentation (runbooks, onboarding guides, troubleshooting, reference architecture) to support platform adoption.
  • Provide operational support for security tooling integrations, including triage of pipeline failures, report ingestion issues, and tooling upgrades.
  • Contribute to continuous improvement of DevSecOps strategy, governance, and compliance alignment through automation and measurable outcomes.
Required Skills
  • 8-12 years of experience in DevOps / DevSecOps / Security Engineering / Platform Engineering roles with strong CI/CD ownership.
  • Demonstrated technical leadership experience (e.g., leading initiatives, mentoring engineers, defining standards, driving cross-team adoption).
  • Strong hands-on experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, GitLab CI).
  • Practical expertise in: SBOM generation and management (e.g., CycloneDX or SPDX concepts, dependency discovery, artifact association)
  • Secret scanning integrations and tuning SAST integration, configuration, and triage workflows
  • Experience automating generation, transformation, and publishing of security results (APIs, JSON handling, pipelines-as-code, scripting).
  • Experience integrating with or operating vulnerability/SBOM platforms such as Dependency-Track and DefectDojo (or equivalent tools).
  • Strong scripting skills (Python, PowerShell, Bash, etc.) for automation and tooling glue.
  • Strong troubleshooting skills across build systems, SCM workflows, containers/artifacts, and security tooling outputs.
  • Ability to write clear technical documentation and drive adoption across teams.
Desirable Skills
  • Experience improving SBOM quality metrics and implementing policy gates (completeness checks, schema validation, build provenance, license metadata enrichment).
  • Familiarity with SCA/vulnerability workflows and risk triage at scale (severity normalization, deduplication, SLA reporting).
  • Experience with container security and artifact scanning (images, binaries, registries), plus SBOM provenance linkage.
  • Knowledge of secure software supply chain practices (SLSA concepts, signing/attestation, provenance, dependency pinning).
  • Experience working in regulated or security-focused environments with strong auditability requirements.
  • Exposure to internal developer platform patterns (golden pipelines, reusable actions, templates, centralized governance).

Experience Level Senior Level

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Deputy Director - DevSecOps
Deputy Director - DevSecOps

PepsiCo • Hyderabad

On-site
INR 3,500,000 - 5,500,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,500,000 - 2,000,000
DevSecOps (Security test lead) Engineer
DevSecOps (Security test lead) Engineer

D-techworks • Mumbai, Bengaluru

On-site
INR 2,500,000 - 4,000,000
DevSecOps Process & Tools - Principal Engineer
DevSecOps Process & Tools - Principal Engineer

Pepsico • Hyderabad

On-site
INR 4,500,000 - 6,500,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

IntraEdge • Hyderabad

On-site
INR 2,000,000 - 4,200,000
Senior DevSecOps Engineer (Azure Infrastructure Engineer)
Senior DevSecOps Engineer (Azure Infrastructure Engineer)

Cubic Transportation • Hyderabad

On-site
INR 350,000 - 550,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Lonvec Technologies Private Limited • Bengaluru

On-site
INR 2,600,000 - 4,000,000
Devsecops Expert
Devsecops Expert

Classic Search • Bengaluru

On-site
INR 4,000,000 - 6,500,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
Devsecops Engineer - Azure, Ci/CD
Devsecops Engineer - Azure, Ci/CD

HCLTech • Dadri, Chennai District, Bengaluru

Hybrid
INR 1,200,000 - 1,800,000