Start Your Search Here

push notification bell

Would you like to receive notifications about jobs in Plano?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

Samprasoft

Plano / Global

DevSecOps Security Engineer

Job Description

Devsecops Or Application Security HireResponsibilities:We are looking for a DevSecOps or application security hire. Location preference: TX, PA, NC, AZ. Provide technical security risk oversight of our Infosys partner including:Review and approval of security vulnerability acceptance requestsEnsure adherence to security requirements and vulnerability remediation SLAsActive participation in recurring security and vulnerability oversight meetingsAssist with daily DevSecOps security assurance operational and enforcement processes for our current suite of security automation tools.Provide support to IT teams for enhancing security and protection controls in relation to security automation, CI/CD, DevSecOps, and vulnerability remediation.Participate in DevSecOps security assurance projects and initiatives as assigned.Qualifications:Experience working with widely used security automation technologies such as:Static application security testing (SAST)Software composition analysis (SCA)Open source software vulnerabilitiesDynamic application security testing (DAST)Interactive application security testing (IAST)Container and image security scanningAPI security scanningPractical experience analyzing vulnerability data to understand and communicate risks, concerns and outcomes of decisionsExperience with CI/CD pipeline tools and technologies such as Bamboo, Jenkins, GitHub, GitHub Actions, Artifactory, Nexus, Docker, Kubernetes, Ansible, or Terraform, and Atlassian Suite (Jira, Confluence, Bitbucket)Working knowledge of OWASP Top 10, SANS Top 25, NIST/NVD (National Vulnerability Database), CVSS (Common Vulnerability Scoring System), CVE (Common Vulnerabilities and Exposures), technical security vulnerability remediation/mitigation, and security risk oversightStrong, demonstrated analysis and problem-solving, communication, interpersonal skillsProfessional security certification in good standing such as ISC2 CISSP, ISC2 Certified Secure Software Lifecycle Professional (CSSLP), GIAC Security Essentials Certification (GSEC), or CompTIA Security+Recent software engineering experience is a plusExperience with scripting languages such as PowerShell, Python, Bash, or Postman is a plusTop 3 skills:Working knowledge of OWASP Top 10, SANS Top 25, NIST/NVD (National Vulnerability Database), CVSS (Common Vulnerability Scoring System), CVE (Common Vulnerabilities and Exposures), technical security vulnerability remediation/mitigation, and security risk oversightPractical experience analyzing vulnerability data to understand and communicate risks, concerns and outcomes of decisions.
Apply Now

Similar Opportunities

View all jobs

Get Job Alerts

Don't miss the perfect fit. Get Daily curated job alerts.

Job Title or Keyword(s)
Location