DevSecOps SME - Contract
Core
Design, implement, and roll-out application security scanning standards across enterprise engineering pipelines.
Role type
Senior DevSecOps Engineer (Contract)
Builds
Automated security testing stages and quality gates within CI/CD pipelines
Domain
Software Engineering / Application Security
Required skills
SAST/SCA/DAST platform implementation, CI/CD pipeline integration, OWASP Top 10 knowledge, dependency vulnerability management, scripting (Python/Bash/PowerShell), API automation
Preferred skills
Enterprise security tooling deployment, secure coding standards establishment, developer triage workflows
Technologies
Checkmarx, SonarQube, Veracode, Snyk, Fortify, OWASP ZAP, GitLab CI, GitHub Actions, Azure DevOps, Jenkins
Responsibilities
Configure and deploy code scanning platforms across enterprise repositories; Establish baseline rulesets and enforcement mechanisms for SAST, SCA, and DAST; Embed automated security testing stages into CI/CD pipelines; Define operational scope of security scanning and optimize rulesets; Provide guided remediation and build developer-first security practices
Seniority
Senior, hands-on IC