Job description
Key Responsibilities
DevSecOps & CI/CD Security
- Design, build, and maintain secure CI/CD pipelines with integrated SAST, DAST, SCA, secrets detection, container scanning, and SBOM generation.
- Implement and tune security tools such as GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, IriusRisk, or equivalent solutions.
- Establish security gates, guardrails, reusable pipeline templates, and secure engineering standards.
- Balance security coverage with pipeline performance and developer productivity.
Application Security & Vulnerability Management
- Conduct and support SAST, DAST, API security testing, penetration testing, and vulnerability assessments.
- Triage, prioritize, and risk-rate security findings and provide actionable remediation guidance.
- Validate remediation and track vulnerabilities through closure.
- Monitor CVEs and emerging vulnerabilities, including zero-day threats, and coordinate appropriate response with engineering and platform teams.
- Identify recurring security weaknesses and recommend improvements to prevent similar vulnerabilities.
Secure Coding & Developer Enablement
- Perform secure code and pull-request reviews and work directly with developers to remediate security issues.
- Develop and maintain secure coding standards aligned with OWASP principles.
- Provide guidance on authentication, authorization, injection prevention, secrets management, cryptography, and other application security practices.
- Conduct developer security awareness sessions, secure coding workshops, threat-modeling walkthroughs, and hands-on security labs.
Azure & Cloud Security
- Implement and validate Azure security controls covering:
- Identity and Access Management (IAM)
- Network segmentation
- Azure Key Vault and secrets management
- Container and Kubernetes security
- Storage and data encryption
- Cloud security posture management (CSPM)
- Review and secure Infrastructure-as-Code (IaC) using Terraform, Bicep, or equivalent technologies.
- Identify cloud misconfigurations and security risks before deployment to production.
Collaboration & Governance
- Partner with Security Architects, Threat Modeling/Risk Specialists, Engineering Leads, Platform Owners, and Security Champions.
- Translate security and architectural requirements into practical controls at the code, pipeline, cloud, and infrastructure levels.
- Maintain security tooling coverage, pipeline effectiveness, vulnerability closure metrics, and recurring risk trends.
- Support InfoSec, ICS, and audit activities, including evidence gathering and control validation.
- Ensure security engineering practices align with frameworks and standards such as NIST, OWASP, and OWASP SAMM.