NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
11 days ago
Apply with autofill
Apply with autofill
Atos·11 days ago
11 days ago

J_ P_ Nagar, Bengaluru, Karnat Sr_ Devsecops Security Engineer

Mid · 2-5 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at Atos

How you compare FREE

?
Your scoreYour score: not yet known

Must-have skills for this role

  • sast
  • dast
  • ci/cd
  • fuzzing

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs.
  • Perform and review Static Application Security Testing (SAST), including detailed source code review.
  • Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments.
  • Design and execute fuzzing activities for applications and APIs.
  • Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components.
  • Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities.
  • Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes.
  • Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices.
  • Define and implement security testing practices across the SDLC.
  • Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles.
  • Identify security test scenarios during sprint planning.
  • Create, maintain, and automate security test cases.

What they're looking for

  • 5–7 years of experience in Application Security Testing, DevSecOps.
  • Strong hands-on experience in web application security testing and API security testing.
  • Proven experience in SAST (secure code review), DAST, Fuzzing, Software Composition Analysis (SCA), CI/CD pipeline security testing, Software supply chain security testing.
  • Strong understanding of SDLC, secure coding practices, and shift-left security.
  • Experience creating and automating security test cases in agile/sprint-based environments.
  • Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
  • Experience working with development, DevOps, QA, and product teams.
  • Strong analytical, communication, and stakeholder management skills.

Nice to have

  • Experience with cloud platforms such as AWS, Azure, or GCP.
  • Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security.
  • Experience integrating security tools into CI/CD pipelines.
  • Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

We are looking for a highly experienced Senior DevSecOps Security Engineer to lead cybersecurity testing initiatives across web applications, APIs, CI/CD pipelines, and software supply chain environments. The ideal candidate will have strong hands-on experience integrating security into the SDLC and driving secure-by-design practices across development, QA, and production environments. Key Responsibilities • Lead and execute DevSecOps operations and cybersecurity testing for web applications and APIs. • Perform and review Static Application Security Testing (SAST), including detailed source code review. • Conduct Dynamic Application Security Testing (DAST) across development and pre-production environments. • Design and execute fuzzing activities for applications and APIs. • Perform Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and third-party components. • Assess and test CI/CD pipelines for security gaps, misconfigurations, and privilege escalation opportunities. • Conduct software supply chain security testing and identify risks in build, artifact, and deployment processes. • Drive security testing before the Quality Assurance (QA) phase to enable shift-left security practices. • Define and implement security testing practices across the SDLC. • Work closely with development, QA, DevOps, and architecture teams to embed cybersecurity testing into sprint cycles. • Identify security test scenarios during sprint planning. • Create, maintain, and automate security test cases. • Execute and validate security test cases across Dev, UAT, and Production promotion stages. • Review and validate remediation activities and provide risk-based recommendations. • Mentor junior engineers, review their reports and contribute to security best practices, standards, and governance. Required Skills and Experience • 5–7 years of experience in Application Security Testing, DevSecOps. • Strong hands-on experience in web application security testing and API security testing. • Proven experience in: o SAST (secure code review) o DAST o Fuzzing o Software Composition Analysis (SCA) o CI/CD pipeline security testing o Software supply chain security testing • Strong understanding of SDLC, secure coding practices, and shift-left security. • Experience creating and automating security test cases in agile/sprint-based environments. • Familiarity with OWASP Top 10, API Security Top 10, and common application security vulnerabilities. • Experience working with development, DevOps, QA, and product teams. • Strong analytical, communication, and stakeholder management skills. Tools Knowledge • JFrog • SonarQube • Burp Suite • Nessus • XRAY • JIRA • Microsoft Threat Modeling Tool • Postman Preferred Qualifications • Experience with cloud platforms such as AWS, Azure, or GCP. • Knowledge of container security, Kubernetes security, and Infrastructure-as-Code security. • Experience integrating security tools into CI/CD pipelines. • Relevant certifications such as CISSP, CSSLP, GWAPT, or DevSecOps-related certifications.

Company

Atos

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Atos's careers site·first seen 11 Sept 2026·last verified 11 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer [Remote-US] at quanataremote –match not yet calculated
  • I&C and Cybersecurity Engineer – Control Systems Specialist at GE VernovaAshalim–match not yet calculated
  • IT Security Engineer at RHB BankSelangor–match not yet calculated
  • Security Engineer (SIEM & SOAR) | Associate Manager at Accenture–match not yet calculated
  • Network and Security Engineer at DNV–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom
  • Retail Sales Associate jobs in United States