Lead Security Test Engineer – DevSecOps

Mythri Consulting LLC

Englewood (NJ)

Hybrid

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Mythri Consulting LLC in New Jersey is seeking a Lead Security Test Engineer with strong DevSecOps and application security experience to design, implement, and execute security testing across the software development lifecycle.

Applicants should have hands-on experience with SAST, DAST, SCA, API security, penetration testing, vulnerability assessment, and threat modeling, and be able to integrate security checks into Jenkins, GitHub Actions, GitLab CI/CD, or Azure DevOps.

Qualifications

  • Experience in application security testing across SDLC.
  • Hands-on SAST/DAST/SCA and API security testing.
  • Ability to integrate security controls into CI/CD pipelines.
  • Familiarity with threat modeling and OWASP frameworks.
  • Strong communication with Dev, QA, DevOps, Cloud and Security teams.

Responsibilities

  • Design and execute security testing strategies for web apps, APIs, microservices, mobile apps, and cloud environments.
  • Perform vulnerability assessments and penetration testing and validate remediation.
  • Integrate security testing tools and automated gates into CI/CD pipelines.
  • Lead shift-left security and DevSecOps practices in the SDLC.
  • Collaborate with cross-functional teams to remediate vulnerabilities.

Skills

Application Security Testing
SAST
DAST
SCA
API Security Testing
Penetration Testing
Vulnerability Assessment
Threat Modeling
OWASP
DevSecOps
Security Test Automation
REST / GraphQL API Security
CI/CD Security Integration

Tools

Jenkins
GitHub Actions
GitLab CI/CD
Azure DevOps
Docker
Kubernetes
AWS Secrets Manager

Job description

Location: New Jersey, USA (Hybrid – 3 Days Onsite) (Mandate in person)

Experience: 10+ Years

Face to Face Interview Required

Job Summary

We are looking for a Lead Security Test Engineer with strong DevSecOps and Application Security experience to design, implement, and execute security testing throughout the software development lifecycle.

The ideal candidate will have hands‑on experience with SAST, DAST, SCA, API Security, Penetration Testing, Vulnerability Assessment, and Threat Modeling, along with the ability to integrate security testing into CI/CD pipelines.

Key Responsibilities
  • Design and execute security testing strategies for web applications, APIs, microservices, mobile applications, and cloud environments.
  • Perform SAST, DAST, SCA, API security, container security, and infrastructure security testing.
  • Conduct vulnerability assessments and penetration testing and validate remediation.
  • Integrate security testing tools and automated security gates into CI/CD pipelines.
  • Collaborate with Development, QA, DevOps, Cloud, and Security teams to identify and remediate vulnerabilities early.
  • Implement shift-left security and DevSecOps controls across the SDLC.
  • Configure and manage security tools for SAST, DAST, SCA, secrets scanning, container scanning, and IaC security.
  • Perform security testing of Docker/Kubernetes environments.
  • Test REST and GraphQL APIs, including authentication and authorization mechanisms.
  • Integrate security checks with Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, or similar tools.
  • Analyze vulnerability findings, prioritize risks, and track remediation through closure.
  • Develop security test cases, automation frameworks, reports, and security metrics.
  • Participate in threat modeling and security architecture reviews.
  • Support security and compliance standards including OWASP Top 10, OWASP ASVS, SANS, NIST, and CIS Controls.
  • Stay current with emerging security threats, testing methodologies, and DevSecOps tools.
Mandatory Skills
  • Application Security Testing
  • SAST
  • DAST
  • SCA
  • API Security Testing
  • Penetration Testing
  • Vulnerability Assessment
  • Threat Modeling
  • OWASP
  • DevSecOps
  • Security Test Automation
  • CI/CD Security Integration
  • AWS Secrets Manager
  • REST / GraphQL API Security
  • Jenkins / GitHub Actions / GitLab CI/CD / Azure DevOps
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Test Engineer DevSecOps
Lead Security Test Engineer DevSecOps

Prudent Technologies and Consulting • Englewood Cliffs (NJ)

Hybrid
USD 120,000 - 180,000
Lead DevSecOps Security Test Engineer
Lead DevSecOps Security Test Engineer

Mythri Consulting LLC • Englewood (NJ)

Hybrid
USD 120,000 - 180,000
Lead DevSecOps Security Test Engineer
Lead DevSecOps Security Test Engineer

Prudent Technologies and Consulting • Englewood Cliffs (NJ)

Hybrid
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Jr. Application Security Specialist
Jr. Application Security Specialist

New York Technology Partners • Princeton (NJ)

On-site
USD 70,000 - 90,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance