DevSecOps Application Security Engineer

Infosys

Richardson (TX)

On-site

USD 110,000 - 170,000

Full time

38 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Infosys in Richardson, TX is seeking a security-focused engineer to collaborate with client and internal teams to resolve incidents, perform root cause analyses, and document preventive recommendations. You will assess IT infrastructure, prepare actionable reports, and support due diligence to identify maturity and improvement opportunities.

The role covers design of scalable, cost-effective infrastructure, release alignment, deployments, testing, and maintenance.

Qualifications

  • SAST/SCA with GHAS and DAST with Burp Suite.
  • Perform vulnerability analysis and prioritize remediation steps.
  • Prepare clear technical findings for audits and stakeholders.
  • Coordinate with development teams on secure coding practices.

Responsibilities

  • Collaborate with internal and client teams to resolve incidents and document preventive actions.
  • Evaluate client IT infrastructure and prepare actionable assessment reports.
  • Design scalable, cost-effective IT infrastructure and create technical docs.
  • Align release schedules and manage deployments with post-deployment testing.
  • Coordinate maintenance, emergency fixes, and technology upgrades.
  • Analyze performance data and support capacity planning.
  • Conduct security checks, drills, and audits; implement security measures.
  • Identify automation opportunities to improve infrastructure processes.
  • Liaise with onsite, offshore, and vendor teams to document project requirements.
  • Build a centralized knowledge repository from insights across projects.

Tools

GHAS
Burp Suite
OWASP
Fortify
SonarQube
Netsparker
Fortify on Demand
BlackDuck
Dependabot

Job description

In the assigned Job Role, your Area Of Responsibility will be as below:
  • Collaborate with internal and client teams to resolve complex incidents, conduct root cause analyses, and document findings with preventive recommendations
  • Participate in evaluation of client IT infrastructure, prepare actionable assessment reports, and support due diligence to document infrastructure maturity and improvement opportunities
  • Contribute to the design of scalable, cost-effective IT infrastructure solutions, review reusable components, and develop technical documentation for deployed systems
  • Align release schedules and environment readiness, execute deployments as per protocols, perform post-deployment testing, and manage version control to track changes
  • Co-ordinate maintenance schedules, emergency fixes, and technology upgrades while ensuring uninterrupted integration into existing systems and processes
  • Facilitate performance data analysis across systems, coordinate insights on system behavior, and support capacity planning to optimize performance
  • Conduct security checks, recovery drills, and compliance audits, implement security measures, and coordinate continuity plans to maintain adherence to standards
  • Gather feedback to identify automation opportunities, analyze existing infrastructure processes, and propose enhancements for efficiency gains
  • Act as liaison with onsite, offshore, and vendor teams to document project requirements, ensuring effective collaboration
  • Develop a centralized repository of technical and procedural knowledge, leveraging insights from other projects to drive efficiency and retain organizational expertise
Your contribution to the team:
  • A collaborative spirit and excellent communication skills.
  • Ability to handle complex incidents and implement resolutions
  • A knack for conducting IT infrastructure assessment and identifying key optimization opportunities
  • Focused approach towards deployment management, system optimization, and process automation initiatives including sector specific focus
  • The ability to work with cross-functional teams
Required Skills :
  • Application Security Testing: Conduct SAST/SCA using GHAS and DAST using Burp Suite; validate and classify vulnerabilities aligned with OWASP.
  • DevSecOps & Integration: Integrate GHAS into CI/CD, automate scans across SDLC, configure policies, reduce false positives, and enable shift-left security with development teams.
  • Vulnerability Management: Analyze findings, provide remediation guidance, track vulnerabilities through lifecycle, and support risk-based prioritization.
  • Reporting & Stakeholder Management: Prepare technical and executive reports, communicate findings with stakeholders, and support audits, compliance, and AppSec initiatives.
Preferred Skills :
  • Security Advisory & Review: Conduct secure code reviews and architecture level assessments; Coordinate with development teams on secure coding and mitigation strategies.
  • Knowledge Of: SDLC and DevSecOps practices, microservices/API/cloud security, strong analytical/problem-solving skills, and stakeholder communication/consulting experience.
Good to Have:
  • Exposure to SAST (Fortify, SonarQube), DAST (Netsparker, Fortify on Demand), and SCA (BlackDuck, Dependabot) tools.
  • Experience in threat modeling and architecture reviews.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Vytalize Health • Kansas (OH)

On-site
USD 120,000 - 160,000
DevSecOps Security Engineer - Infosys Technologies Ltd
DevSecOps Security Engineer - Infosys Technologies Ltd

OpenTalent • Richardson (TX)

Hybrid
USD 110,000 - 150,000
Application Offensive Security Consultant
Application Offensive Security Consultant

StaffWorthy • Jersey City (NJ)

On-site
USD 90,000 - 120,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
DevSecOps – Staff Engineer
DevSecOps – Staff Engineer

Marketplace Operations Inc. • Tennessee

On-site
USD 120,000 - 150,000
Wellness Reimbursement Program
Office Commutation Reimbursement Program
Paid parental leaves
DevSecOps Engineer (Web Security Focus)
DevSecOps Engineer (Web Security Focus)

shefsolutionsllc • Los Angeles (CA)

On-site
USD 120,000 - 180,000