Description
A leading financial institution is seeking a DevSecOps Engineer to enhance application security across its technology portfolio. Reporting to the CISO, this role supports a regulatory initiative focused on embedding secure practices into CI / CD pipelines and modern development workflows. Success means measurable improvements in vulnerability management, container security, and developer awareness.
What You’ll Tackle
- Conduct application security assessments including SAST, SCA, DAST, and penetration testing.
- Partner with engineering teams to perform threat modeling and integrate security controls.
- Build and maintain CI / CD pipelines with embedded security gates and testing tools.
- Configure and manage security platforms (e.g., Checkmarx, Qualys, JFrog Xray, Twistlock).
- Evaluate and enhance container and runtime security in Kubernetes / OpenShift environments.
- Provide developer training on secure coding practices.
- Document findings, remediation plans, and compliance alignment.
- Collaborate with IT, compliance, and DevOps teams to improve overall security posture.
What You Bring
5+ years in application or DevSecOps security within financial services.Strong command of SAST, SCA, DAST, and threat modeling methodologies.Proven success embedding security tools within CI / CD (Jenkins, Azure DevOps).Hands-on experience with container and cloud security (AWS, Azure).Knowledge of OWASP Top 10, PCI DSS, NIST, and ISO 27001.Excellent communication and documentation skills.Bachelor’s degree in Computer Science, Information Security, or related field.Familiarity with runtime protection tools and container hardening.Experience training developers or influencing secure SDLC practices.