Role: DevSecOps Engineer
Location: All Persistent Location
Experience: 7 to 10 Years
Job Type: Full Time Employment
What You'll Do:
Integrate security controls into CI/CD pipelines to enable secure application delivery
Lead and manage application, container, and cloud vulnerability scanning activities
Implement and operate SAST, SCA, DAST, Secrets Detection, and IaC security scans
Analyze vulnerability findings and provide actionable remediation guidance to development teams
Track, prioritize, and support vulnerability remediation across projects
Automate security scanning, reporting, and alerting workflows
Collaborate with DevOps and cloud teams to embed DevSecOps best practices
Support threat modeling and risk assessments for applications and infrastructure
Assist with penetration testing efforts and validate fix closures
Maintain and administer GitLab CI/CD security features and integrations
Expertise You'll Bring:
Strong experience in DevSecOps and Vulnerability Management within CI/CD environments
Hands-on expertise with SAST, SCA, DAST, Secrets Detection, and IaC security scanning
Solid understanding of CI/CD pipelines using GitLab (preferred) or similar tools
Practical experience with cloud security on AWS, Azure, or GCP
Hands-on knowledge of container and Kubernetes security
Experience using tools such as Trivy, Terraform, Jenkins, Burp Suite, or similar
Ability to analyze vulnerability findings and provide clear remediation guidance
Understanding of secure coding practices and cloud-native security concepts
Exposure to threat modeling, risk assessment, and penetration testing support
Scripting or automation experience using Python, Bash, or JavaScript is a plusRole & responsibilities
Preferred candidate profile
Perks and benefits

Keyskills: Devsecops Vulnerability Management Ci/Cd Threat Modeling Security