Source description
About the role
Role Profile
Client is looking for a DevSecOps Engineer who will facilitate and enable Group Application Security to establish, operate and further develop the Team's automated scanning capabilities. The successful candidate will be working closely with Application Security, development teams and central CI/CD tooling teams to embed SAST and SCA tooling into build pipelines.
Furthermore, the ideal candidate will have the following traits:
Critical thinker
Ability to work well under pressure
Hands-on experience in enterprise scale implementations of SAST and SCA
Hands-on experience in developing and maintaining tools
Excellent Scripting skills (Python, bash, PowerShell)
Knowledge of CI/CD tools (Jenkins, Bamboo, TFS) and experience in integrating security tools in build pipelines
Hands-on experience with source control (Git, GitLab, BitBucket)
Hands-on experience with Configuration Management and Infrastructure as Code tools (Ansible/Terraform)
Knowledgeable in AWS
Good verbal and written communication skills, with particular ability to communicate technical concepts to non-technical audiences
Willing to expand skill set
Practical application of lessons learned into the team's practices
Beneficial skills and experience
Prior security testing experience
Ability to triage static analysis findings
Deep understanding of common as well as emerging vulnerabilities and how they manifest in different types of applications (web applications, thick clients, APIs, etc.)
Familiarity with OWASP Top 10, SANS Top 25, NIST and ASVS
Familiarity with emerging testing methodologies, such as IAST Reference: 19-03576
More at eTeam