Sr. Devsecops Security Engineer

Atos

Bhopal

On-site

INR 1,800,000 - 2,400,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Atos in India is seeking a Senior DevSecOps Security Engineer to lead cybersecurity testing across web apps, APIs, CI/CD pipelines, and software supply chains. You will embed secure-by-design practices across development, QA, and production, drive shift-left testing, and mentor junior engineers while collaborating with cross-functional teams.

You will apply hands-on expertise in SAST, DAST, SCA, and CI/CD security while aligning with SDLC security standards and OWASP guidance.

Qualifications

  • 5-7 years in Application Security Testing or DevSecOps.
  • Hands-on web and API security testing experience.
  • Experience with SAST/DAST, SCA, and CI/CD security testing.
  • Strong SDLC security and shift-left practices.
  • Experience automating security test cases in Agile.
  • Familiarity with OWASP Top 10 and API Security Top 10.
  • Proven collaboration with Dev, QA, and product teams.
  • Excellent analytical and stakeholder management skills.

Responsibilities

  • Lead DevSecOps operations and security testing for apps and APIs.
  • Perform SAST and code reviews.
  • Conduct DAST across development and pre-prod.
  • Design fuzzing activities for apps and APIs.
  • Perform SCA to identify vulnerable dependencies.
  • Assess security in CI/CD pipelines and build processes.
  • Mentor junior engineers and share best practices.

Skills

AppSec Testing
DevSecOps
Web Security
API Security
SAST/DAST
CI/CD Security
SCA
SDLC Security
Automation
OWASP Top10
Stakeholder Mgmt

Tools

JFrog
SonarQube
Burp Suite
Nessus
XRAY
JIRA
Threat Modeling Tool
Postman

Job description

We are looking for a highly experienced Senior DevSecOps Security Engineer to lead cybersecurity testing initiatives across web applications, APIs, CI/CD pipelines, and software supply chain environments. The ideal candidate will have strong hands-on experience integrating security into the SDLC and driving secure-by-design practices across development, QA, and production environments.

Key Responsibilities
  • Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs.
  • Perform and review Static Application Security Testing (SAST), including detailed source code review.
  • Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments.
  • Design and execute fuzzing activities for applications and APIs.
  • Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components.
  • Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities.
  • Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes.
  • Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices.
  • Define and implement security testing practices across the SDLC.
  • Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles.
  • Identify security test scenarios during sprint planning.
  • Create, maintain, and automate security test cases.
  • Execute and validate security test cases across Dev, UAT, and Production promotion stages.
  • Review and validate remediation activities and provide risk-based recommendations.Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance.
Required Skills and Experience
  • 5-7 years of experience in Application Security Testing, DevSecOps.
  • Strong hands-on experience in web application security testing and API security testing.
  • Proven experience in oSAST (secure code review)oDASToFuzzingoSoftware Composition Analysis (SCA)oCI/CD pipeline security testingoSoftware supply chain security testing
  • Strong understanding of SDLC, secure coding practices, and shift-left security.
  • Experience creating and automating security test cases in agile/sprint-based environments.
  • Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
  • Experience working with development, DevOps, QA, and product teams.
  • Strong analytical, communication, and stakeholder management skills.
Tools Knowledge
  • JFrog
  • SonarQube
  • Burp Suite
  • Nessus
  • XRAY
  • JIRA
  • Microsoft Threat Modeling Tool
  • Postman
Preferred Qualifications
  • Experience with cloud platforms such as AWS, Azure, or GCP.
  • Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security.
  • Experience integrating security tools into CI/CD pipelines.
  • Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Devsecops Security Engineer
Sr. Devsecops Security Engineer

Atos SE • Bengaluru

On-site
INR 2,500,000 - 4,000,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
DevSecOps Security Engineer
DevSecOps Security Engineer

Ford • Chennai District

On-site
INR 1,500,000 - 1,800,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,500,000 - 2,000,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

IntraEdge • Hyderabad

On-site
INR 2,000,000 - 4,200,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer (SAST / DAST / DevSecOps / SCA)
Application Security Engineer (SAST / DAST / DevSecOps / SCA)

Qualizeal India • Hyderabad

On-site
INR 1,200,000 - 1,800,000