This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Application Security DevSecOps Specialist will play a vital role in integrating security into the software development lifecycle. This position requires a bachelor’s degree in Cybersecurity, Computer Science, or Software Engineering, along with 3-5 years of experience in application security engineering. The ideal candidate will have proficiency in multiple programming languages and extensive experience with application security tools. Responsibilities include conducting security assessments, mentoring engineers, and designing security automation within CI/CD workflows.
Job Responsibility:
Incorporate security controls and standards into all phases of the software development lifecycle (SDLC)
Collaborate with developers to adopt secure coding practices, including OWASP compliance
Conduct threat modeling and evaluate design documents to identify security vulnerabilities
Establish security requirements and acceptance criteria for application development projects
Design and implement security automation within CI/CD workflows using tools for SAST, DAST, IAST, SCA and compliance monitoring
Develop custom security testing frameworks compatible with agile and DevSecOps models
Conduct infrastructure-as-code (IaC) configuration checks and enforce compliance policies
Automate secrets scanning, credential hygiene practices, and dependency vulnerability reviews
Execute static (SAST) and dynamic (DAST) application security assessments
Perform manual penetration testing and secure code reviews to detect risks
Analyze application dependencies and third-party components, ensuring vulnerability remediation
Validate security fixes via rigorous regression testing and secure deployment methods
Prepare training initiatives for developers on secure coding practices, application security principles, and DevSecOps workflows
Create and disseminate security documentation, guidelines, and playbooks for developers and architects
Mentor engineers to adopt security-first product development and incident prevention strategies
Establish and support developer security champion programmes within agile teams
Implement robust security controls for containerized workloads in Docker, Kubernetes, and similar platforms
Design and secure API endpoints and microservices architectures
Leverage cloud security services on AWS, Azure, or GCP to deliver secure, scalable solutions
Advocate for best practices in secret management, repository vaulting, and cloud-native application monitoring
Requirements:
Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or equivalent experience
Minimum 3-5 years of experience in application security engineering
Familiarity with implementing container security policies and securing high-performance CI/CD development ecosystems
Proficiency in multiple programming languages (e.g., Java, Python, JavaScript, Go, .NET)