Source description
About the role
Embed security best practices into CI/CD pipelines and infrastructure as code (IaC) Implement and manage security tools such as SAST, DAST, SCA, secrets scanning, and container scanning Collaborate with developers, DevOps, and security teams to remediate vulnerabilities Automate compliance checks and security testing within build and deployment workflows Manage cloud security configurations ( Azure)and policies Monitor and respond to security incidents in CI/CD and production environments Maintain secure configurations of containers, Kubernetes, and other orchestration platforms Conduct threat modeling, risk assessments, and security reviews for new projects Ensure compliance with security frameworks (e.g., NIST, ISO 27001, SOC 2, CIS Benchmarks) Document security controls, processes, and incidents Required Qualifications: 3–6 years of experience in DevOps, cybersecurity, or related roles Hands-on experience with CI/CD tools (e.g., GitHub Actions, GitLab CI, Jenkins) Strong understanding of application security concepts and secure coding practices Familiarity with tools like SonarQube, Checkmarx, Veracode, Aqua, Snyk, Trivy, or similar Experience with Docker, Kubernetes, and container security Proficiency with cloud platforms (Azure) and security services Strong scripting skills (e.g., Python, Bash, or PowerShell)
More at Tata Consultancy Services