Security Engineer, Specialist
Core
Security Engineer specializing in application security and DevSecOps to ensure secure, compliant digital solutions and operationalize automated security controls throughout the SDLC.
Role type
Specialist Application Security Engineer (DevSecOps)
Builds
Secure CI/CD pipelines, automated security gates, and compliant release artifacts for digital products.
Domain
Application Security / DevSecOps / Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Secure SDLC principles, OWASP Top 10, container security, Kubernetes/OpenShift security, image signing/verification, SBOM generation, secrets management, SAST/DAST tuning, threat modeling, vulnerability lifecycle management
Preferred skills
Azure DevOps Server, JFrog Artifactory, HashiCorp Vault, Cert-Manager, Sigstore/Cosign, AppDynamics, BMC, Azure Monitoring, government or highly regulated enterprise sector experience
Technologies
Fortify SAST/DAST, Azure DevOps Server, JFrog Artifactory, HashiCorp Vault, Cert-Manager, Kubernetes, OpenShift, Sigstore, Cosign, AppDynamics, BMC, SecurEnvoy MFA
Responsibilities
Engage with clients and stakeholders to gather security requirements and compliance goals; Deliver security dashboards and reporting frameworks showcasing vulnerability triage and remediation; Configure and tune Fortify SAST/DAST and govern exception workflows; Implement automated SSL/TLS certificate renewals and secrets management; Build secure pipelines and enforce software supply chain visibility via SBOM integration; Conduct workshops to define Quality Gates, vulnerability SLAs, and secure secrets management patterns; Produce compliance evidence and release packages for Agile releases
Seniority
Mid-level, hands-on IC