Job Summary
Job Responsibilities : DevSecOps Architecture & Strategy • Design, Lead the architecture, implementation, and continuous evolution of the organization’s DevSecOps framework. • Define and enforce security standards across the Software Development Lifecycle (SDLC). • Design scalable security automation within CI/CD pipelines and development workflows. • Establish enterprise DevSecOps governance models, standards, and best practices. • Evaluate and implement modern application security capabilities integrated within DevOps platforms. DevSecOps Platform Engineering • Design and implement a scalable DevSecOps platform architecture integrating application security, infrastructure security, container security, and cloud security controls directly into CI/CD pipelines. • Establish security guardrails and reusable pipeline templates to standardize secure development practices across engineering teams. • Build reusable DevSecOps automation frameworks to enable consistent security enforcement across multiple projects and environments. Security Findings Investigation & Root Cause Analysis • Lead investigation and triage of security findings from cloud security platforms and DevOps security integrations. • Perform deep root cause analysis across source code, pipelines, dependencies, container images, and infrastructure configurations. • Backtrack security findings to their originating component including code commits, dependency updates, container builds, pipeline configurations, or infrastructure deployments. • Implement long-term remediation strategies to eliminate recurring vulnerabilities. • Establish structured vulnerability management workflows and prioritization frameworks. CI/CD Security Engineering • Architect and implement security controls integrated within CI/CD pipelines. • Embed automated security validation within build, test, and release pipelines. • Implement security gates and policy enforcement mechanisms to prevent vulnerable artifacts from progressing through the pipeline. • Optimize pipeline security workflows while maintaining development velocity. • Ensure secure artifact generation, storage, and promotion across pipeline stages. Application Security Automation • Implement automated static code analysis integrated into CI/CD pipelines. • Identify vulnerabilities within application source code across multiple programming languages. • Establish vulnerability severity thresholds and quality gates within pipelines. • Provide developers with actionable security insights and remediation guidance. • Integrate advanced application security scanning capabilities across repositories. • Configure and maintain enterprise-grade application security scanning platforms integrated with development workflows. Open Source & Dependency Security • Implement automated dependency analysis to identify vulnerabilities in open-source libraries and third-party components. • Establish governance and monitoring for third-party component security risks. • Define remediation strategies including upgrades, patches, and risk mitigation plans. • Maintain visibility into dependency usage across development teams. Software Supply Chain Security • Implement security controls to protect the software supply chain, including dependency verification and artifact integrity validation. • Establish processes for software component traceability and secure artifact management across build and release pipelines. • Implement and maintain Software Bill of Materials (SBOM) generation for application dependencies. Container Security • Def
Key Responsibilities
1. To provide level 1 remote desktop support to resolve tickets /provide hardware / software / network problem diagnosis / resolution via telephone/email/chat within agreed SLA of ticket volume and time.
2. To adhere to quality standards (voice and accent , Tech Monitoring), regulatory requirements and company policies.
3. To ensure positive customer experience and CSAT through First Call Resolution and minimum average handling time ( AHT), rejected resolutions / Reopen Cases.
4. To maintain high login Efficiency (Availability) for customers.
5. To update worklogs and follow shift/ escalation process to escalate complex problem to appropriate support specialists/route problems to 2nd and 3rd level IT support staff as the case be.
6. Work on value adding activities such Knowledge base update & self development.
Skill Requirements
Skill Requirement : • 8+ years of experience in DevOps, DevSecOps, or application security engineering. • Proven experience implementing DevSecOps practices at scale in enterprise environments. • Experience leading security automation initiatives within CI/CD ecosystems. DevOps & CI/CD Security • Strong expertise in Azure DevOps pipeline architecture and CI/CD security implementation. • Experience analyzing and remediating security findings from Azure DevOps security integrations and cloud security platforms. • Ability to trace vulnerabilities back to code, pipeline configurations, or deployment artifacts. • Experience implementing security gates and automated security checks within CI/CD pipelines. • Strong understanding of pipeline artifact security, secrets management, and secure build processes. Infrastructure as Code & Terraform • Strong experience working with Terraform for infrastructure provisioning. • Experience implementing security validation for Infrastructure as Code deployments. • Understanding of Terraform state management, module security, and secret handling. • Experience integrating IaC security checks within CI/CD pipelines. Advanced Application Security Platforms • Experience implementing automated static application security testing integrated within CI/CD pipelines. • Experience implementing software composition analysis to detect vulnerabilities in open-source dependencies. • Experience integrating enterprise-grade application security scanning platforms within development workflows. • Understanding of code flow analysis, data flow tracking, and vulnerability path analysis in large codebases. • Experience tuning security scanning results to reduce false positives and improve developer adoption. • Experience configuring security policies, severity thresholds, and remediation workflows within application security platforms. Container & Cloud Security • Strong experience securing containerized workloads. • Experience implementing container image vulnerability scanning within CI/CD pipelines. • Knowledge of secure container image build practices and minimal image strategies. • Experience securing container orchestration environments (Kubernetes or similar). • Experience working with Azure cloud security monitoring platforms. Security Governance & DevSecOps Frameworks • Experience implementing enterprise DevSecOps frameworks. • Experience integrating multiple security tools into CI/CD pipelines. • Knowledge of vulnerability management frameworks and risk prioritization models. • Experience defining security policies, governance models, and compliance controls. • Experience implementing policy-as-code frameworks for infrastructure governance. Development & Infrastructure • Familiarity with programming languages such as Java, .NET, Python, or JavaScript. • Strong experience with Git-based development workflows. • Experience with cloud-native architectures and infrastructure automation. Key Success Indicators • Significant reduction in recurring security findings. • Faster vulnerability remediation across development teams. • Improved security posture across CI/CD pipelines, containers, infrastructure, and cloud environments. • Adoption of secure development practices across engineering teams. • Mature and scalable DevSecOps framework implemented across the organization
Other Requirements
Other Requirement : Developer Security Leadership • Mentor engineering teams on secure development practices. • Provide guidance on vulnerability remediation and secure architecture patterns. • Develop security standards, documentation, and best practice guidelines. • Promote and drive a security-first engineering culture across the organization