Source description
About the role
Job Title: Application Security / SAST / DevSecOps
Location- Bangalore
NP - Immediate to 30 days
Please find the JD and other details –
Job Title
SAST / DevSecOps Security Engineer
Job Summary
We are seeking an experienced SAST / DevSecOps Security Engineer with strong programming skills and deep expertise in Static Application Security Testing (SAST) tools such as Fortify and Checkmarx . The role focuses on secure-by-design enablement , CI/CD integration , false-positive triaging , and hands-on remediation guidance for development teams.
The ideal candidate will work closely with developers, DevOps, and architecture teams to embed security into the SDLC, reduce noise from automated scans, and drive meaningful vulnerability remediation.
Key Responsibilities
Static Application Security Testing (SAST)
Perform and manage SAST scans using:
Fortify (SSC, ScanCentral)
Checkmarx
Configure and customize scan rules, filters, and policies.
Analyze scan results to:
Identify true positives vs false positives
Prioritize vulnerabilities based on exploitability and impact
Maintain high signal-to-noise ratio in SAST findings.
False Positive (FP) Triage & Risk Validation
Perform in-depth FP analysis by:
Reviewing source code
Understanding application logic and data flow
Document justification for FP and accepted risks.
Work with governance teams to maintain consistent triage standards.
Developer Enablement & Remediation Support
Partner with developers to:
Explain SAST findings in code context
Provide secure coding recommendations
Validate fixes and perform rescans
Conduct remediation workshops and secure code reviews.
Assist teams in refactoring vulnerable code patterns.
DevSecOps & CI/CD Integration
Integrate SAST tools into CI/CD pipelines:
Jenkins, GitHub Actions, Azure DevOps
Implement:
Pre-commit / PR-based scans
Build-break or quality-gate policies
Optimize scan performance and reduce pipeline impact.
Support containerized and microservices-based build pipelines.
Secure SDLC & Code Review
Support secure SDLC initiatives including:
Secure design reviews
Threat modeling (good to have)
Perform manual code reviews for high-risk applications.
Define and enforce secure coding standards.
Troubleshooting & Platform Support
Troubleshoot SAST tool issues:
Scan failures
Build integration errors
Language / framework compatibility issues
Support upgrades, migrations, and rulepack updates.
Work closely with vendor support when needed.
Primary Tools & Technologies
Fortify (SSC, ScanCentral, SCA)
Checkmarx
CI/CD: Jenkins, GitHub Actions, Azure DevOps
Languages (strong hands-on required in at least one):
Java
Python
JavaScript / TypeScript
C# / .NET
Build tools: Maven, Gradle, npm, MSBuild
SCM: Git (GitHub, GitLab, Bitbucket)
Required Skills & Qualifications
5–10 years of experience in Application Security / SAST / DevSecOps
Strong programming background with ability to:
Read, understand, and debug production code
Trace data flow and execution paths
Deep hands-on expertise in Fortify and/or Checkmarx
Strong understanding of:
OWASP Top 10
CWE / CVE
Secure coding principles
Experience working in enterprise, CI/CD-driven environments
Good to Have
Experience with SCA tools (Mend, Black Duck, Snyk)
API and microservices security exposure
Infrastructure-as-Code scanning exposure
Certifications:
CSSLP
GWAPT
Secure Code Warrior
Fortify / Checkmarx certifications
Soft Skills
Strong analytical and debugging mindset
Ability to communicate security findings in developer-friendly language
Proactive ownership of remediation outcomes
Strong documentation and collaboration skills
Role Value to Client
Reduced false positives and developer fatigue
Faster remediation and improved code quality
Security embedded early in the SDLC
Scalable and sustainable AppSec program
More at PeopleLogic Business Solutions
Related open roles
IT/OT Network
Bangalore · Hybrid
Crowdstrike Engineer
Bangalore · Hybrid
Infra & Cloud Security Engineer
Mumbai · Hybrid
Data Protection & Certificate Services Analyst (DLP)
Bangalore · Hybrid
Cyber Security Analyst (Threat Intelligence)
Hyderabad · Onsite
Okta (Implementation and integration)
Bangalore · Hybrid