Job Description
Job Title
SAST / DevSecOps Security Engineer
Job Summary
We are seeking an experienced SAST / DevSecOps Security Engineer with strong programming skills and deep expertise in Static Application Security Testing (SAST) tools such as Fortify and Checkmarx. The role focuses on secure-by-design enablement, CI/CD integration, false-positive triaging, and hands-on remediation guidance for development teams.
The ideal candidate will work closely with developers, DevOps, and architecture teams to embed security into the SDLC, reduce noise from automated scans, and drive meaningful vulnerability remediation.
Key Responsibilities
Static Application Security Testing (SAST)
- Perform and manage SAST scans using:
- Fortify (SSC, ScanCentral)
- Checkmarx
- Configure and customize scan rules, filters, and policies.
- Analyze scan results to:
- Identify true positives vs false positives
- Prioritize vulnerabilities based on exploitability and impact
- Maintain high signal-to-noise ratio in SAST findings.
DevSecOps & CI/CD Integration
- Integrate SAST tools into CI/CD pipelines:
- Jenkins, GitHub Actions, Azure DevOps
- Implement:
- Pre-commit / PR-based scans
- Build-break or quality-gate policies
- Optimize scan performance and reduce pipeline impact.
- Support containerized and microservices-based build pipelines.
Secure SDLC & Code Review
- Support secure SDLC initiatives including:
- Secure design reviews
- Threat modeling (good to have)
- Perform manual code reviews for high-risk applications.
- Define and enforce secure coding standards.
Troubleshooting & Platform Support
- Troubleshoot SAST tool issues:
- Scan failures
- Build integration errors
- Language / framework compatibility issues
- Support upgrades, migrations, and rulepack updates.
- Work closely with vendor support when needed.
Primary Tools & Technologies
- Fortify (SSC, ScanCentral, SCA)
- Checkmarx
- CI/CD: Jenkins, GitHub Actions, Azure DevOps
- Languages (strong hands-on required in at least one):
- Java
- Python
- JavaScript / TypeScript
- C# / .NET
- Build tools: Maven, Gradle, npm, MSBuild
- SCM: Git (GitHub, GitLab, Bitbucket)
Required Skills & Qualifications
- 5–10 years of experience in Application Security / SAST / DevSecOps
- Strong programming background with ability to:
- Read, understand, and debug production code
- Trace data flow and execution paths
- Deep hands-on expertise in Fortify and/or Checkmarx
- Strong understanding of:
- OWASP Top 10
- CWE / CVE
- Secure coding principles
- Experience working in enterprise, CI/CD-driven environments
͏
Do
-
Ensuring customer centricity by providing apt cybersecurity
- Monitoring and safeguarding the log sources and security access
- Planning for disaster recovery in the event of any security breaches
- Monitor for attacks, intrusions and unusual, unauthorized or illegal activity
- Performs moderately complex log reviews and forensic analysis to identify unauthorized or unacceptable access to data or systems
- Conduct security assessments, risk analysis and root cause analysis of security incidents
- Handling incidents escalated by the L1 team in 24x7 rotational shifts
- Use advanced analytics tools to determine emerging threat patterns and vulnerabilities
- Completing all tactical security operations tasks associated with this engagement.
- Analyses all the attacks and come up with remedial attack analysis
- Conduct detailed analysis of incidents and create reports and dashboards
-
Stakeholder coordination & audit assistance
- Liaise with stakeholders in relation to cyber security issues and provide future recommendations
- Maintain an information security risk register and assist with internal and external audits relating to information security
- Assist with the creation, maintenance and delivery of cyber security awareness training for colleagues
- Advice and guidance to employees on issues such as spam and unwanted or malicious emails
͏
Deliver
|
No. |
Performance Parameter |
Measure |
|
1. |
Customer centricity |
Timely security breach solutioning to end users, Internal stakeholders & external customers experience |
|
2. |
Process Adherence |
Adherence to SLAâÂÂs (90-95%), response time and resolution time TAT |
͏
͏
Experience: 3-5 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.