DevSecOps Engineer
Ho Chi Minh City - Vietnam
Job Summary
Ready for the next big challenge Grow your career and join our experienced global team transforming the world of M&A software. Be part of the team behind the teams behind the deals. Work with the best. Be the best.
Accountabilities
Position Summary
The DevSecOps Engineer (Product Security Engineer) is responsible for supporting the organizations Product Security program by partnering with software engineering teams to identify assess and remediate application security risks throughout the Software Development Lifecycle (SDLC). This role performs application security assessments supports secure design and development practices and helps integrate security into modern development and DevSecOps processes.
In addition to product security responsibilities the engineer will receive cross-training and provide operational support to the Security Operations team gaining experience in areas such as security monitoring vulnerability management and incident response. This role offers an excellent opportunity for a security professional to develop broad technical expertise while contributing to the protection of the organizations applications infrastructure and information assets.
Duties and Responsibilities
- Review and validate findings from Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Software Composition Analysis (SCA) and container security tools.
- Partner with software engineering teams to identify prioritize and remediate application security vulnerabilities.
- Participate in secure architecture reviews design reviews and threat modeling exercises throughout the Software Development Lifecycle (SDLC).
- Support penetration testing activities and assist with remediation tracking and validation.
- Integrate and promote security best practices within CI/CD pipelines and DevSecOps processes.
- Assist in developing and maintaining secure coding standards application security guidance and security documentation.
- Research emerging application security threats and recommend appropriate mitigations.
- Collaborate with Product Security Engineering DevOps and Infrastructure teams to continuously improve the organizations application security posture.
- Assist with security monitoring alert triage and investigation of potential security events.
- Participate in incident response activities including investigation containment recovery and post-incident reviews.
- Support enterprise vulnerability management activities across applications and infrastructure.
- Assist with maintaining security tools documentation and operational procedures.
- Participate in security awareness initiatives tabletop exercises and continuous improvement efforts.
- Crosstrain with the Security Operations team to support operational security processes and technologies.
Qualifications
- Solid understanding of secure software development lifecycle (SSDLC) principles and secure coding practices.
- Working knowledge of common application security vulnerabilities including the OWASP Top 10 and secure design principles.
- Familiarity with application security testing tools including SAST DAST SCA and vulnerability management platforms.
- Experience with one or more programming or scripting languages such as Java C# JavaScript Python Go PowerShell or Bash.
- Understanding of RESTful APIs web application architectures and modern software development methodologies.
- Familiarity with source code management systems (Git) and CI/CD pipelines.
- Knowledge of cloud platforms (AWS Azure or Google Cloud) and container technologies (Docker Kubernetes) is preferred.
- Familiarity with security monitoring technologies such as SIEM EDR or SOAR platforms is preferred.
- Strong analytical problem-solving and troubleshooting skills.
- Excellent communication and interpersonal skills with the ability to collaborate effectively across technical teams.
- Ability to manage multiple priorities while maintaining attention to detail.
- Strong written and verbal English communication skills.
Education
Bachelors degree in Computer Science Information Security Cybersecurity Information Technology Software Engineering or related technical discipline.
Relevant industry certifications such as CompTIA Security CSSLP GWAPT OSWE or similar certifications are considered a plus.
Experience
- 25 years of experience in Application Security Software Development Information Security Software Engineering or related technical discipline.
Relevant industry certifications such as CompTIA Security CSSLP GWAPT OSWE or similar certifications are considered a plus.