DevSecOps Application Security Engineer
Overview
In this role you will support the design, deployment, and hardening of IT infrastructure for clients in the retail, consumer goods, and logistics sectors. You collaborate with cross-functional and client teams to resolve incidents, assess infrastructure maturity, and drive improvements. You will help deliver scalable, secure, and efficient infrastructure solutions while aligning releases and maintaining documentation and continuity plans. This position offers hands-on security and automation opportunities within a global services context.
Compensation / BenefitsMedical/Dental/Vision/Life InsuranceLong-term/Short-term DisabilityHealth and Dependent Care Reimbursement AccountsInsurance (Accident, Critical Illness, Hospital Indemnity, Legal)401(k) plan and contributionsPaid holidays plus Paid Time Off
ResponsibilitiesCollaborate with internal and client teams to resolve incidents, perform root cause analyses, and document preventive recommendationsEvaluate client IT infrastructure, produce actionable assessment reports, and support due diligenceContribute to designing scalable, cost-effective infrastructure solutions and document deploymentsCoordinate release schedules, environment readiness, deployments, post-deployment testing, and version controlCoordinate maintenance, emergency fixes, and upgrades ensuring integration with existing systemsAnalyze performance data, support capacity planning, and optimize system behaviorConduct security checks, recovery drills, and audits; implement security measures and continuity plansIdentify automation opportunities by analyzing existing processes and proposing enhancementsAct as liaison with onsite, offshore, and vendor teams to document project requirementsDevelop a centralized knowledge repository leveraging insights from other projects to boost efficiency
Key requirementsApplication Security Testing: SAST/SCA with GHAS; DAST with Burp Suite; classify vulnerabilities per OWASPDevSecOps & Integration: Integrate GHAS into CI/CD; automate scans; configure policies; shift-left securityVulnerability Management: Analyze findings; provide remediation guidance; track through lifecycleReporting & Stakeholder Management: Prepare technical and executive reports; support audits and AppSec initiativesCollaborative spirit and excellent communicationAbility to handle complex incidents and implement resolutionsAnalytical problem-solving and stakeholder engagementSAST/SCA (GHAS)DAST (Burp Suite)Vulnerability management tools and methodologies