DevSecOps Lead
New York City, NY - USA
Job Summary
DevSecOps Lead
100% Remote
W2 Candidates only
Minimum Experience: 10 Years
Must have required skills:
Application Security (AppSec)
DevSecOps
SAST (Static Application Security Testing)
SCA (Software Composition Analysis)
Checkmarx
CI/CD Pipeline Security
Source Code Management Platforms
Secure Code Review
Vulnerability Management & Remediation
Software Supply Chain Security
Other Details of Role:
- The Application Security / DevSecOps Engineer will support the clients enterprise Application Security program by integrating security controls and scanning capabilities throughout the software development lifecycle and CI/CD pipelines.
- The resource will work across multiple source code management and DevOps platforms including GitHub GitLab Azure DevOps (ADO) and Jenkins and will be responsible for onboarding applications into security scanning solutions such as Checkmarx.
- Responsibilities include configuring and executing SAST and SCA scans establishing recurring scanning schedules reviewing and analyzing scan results supporting remediation of identified vulnerabilities and integrating security findings with the appropriate development and security workflows.
- The resource should also provide hands-on application security expertise beyond automated tooling including secure code review identification of coding and validation weaknesses review of third-party and open-source libraries/packages and assessment of software supply-chain risks.
- The individual will work closely with application and development teams to identify security gaps provide remediation guidance and help ensure that applications consume trusted and secure software components
Required Skills:
appsecdevsecopssastscacheckmarxci/cdSoftware Supply Chain SecuritySecure Code Review