Devsecops & Threat Modelling Engineer

2 weeks ago


Bengaluru, Karnataka, India Cyraacs™ Full time
The ideal candidate will be responsible for maintaining product and industry knowledge.
You will work in a team-oriented environment that accelerates operational efficiency.

Responsibilities

  • Work along with the Development/Dev Ops team to integrate application security tools in CI/CD pipeline.
  • To understand the supply chain attack in SDLC and Create, develop, and implement security measures/tools in CI/CD pipeline for optimising the Secure SDLC.
  • Work with development, operations, and security teams to validate the false/true positives vulnerabilities and exception process.
  • Work with Development/Dev Ops team to close the vulnerabilities, security misconfigurations and Runtime Threats found in the in CI/CD pipeline, Cloud and Production Environment
  • Conduct Pentest for Kubernetes clusters to find security issues and implement improvement measures.
  • Create and deploy Ia C such as Helm and Terraform codes for deploying the security tools in K8s environment.
  • Work closely with the Developers/Dev Ops teams to investigate threats and respond to security incidents.
  • Evaluate new security policies and tools in Kubernetes Environment and responsible to work with the Dev Ops team to implement the security policies in each product.
  • To understand the application process, Create and Implement K8s Policy configurations for each product in production environment.
  • A strong foundation in security principles and concepts, including confidentiality, integrity, availability, authentication, authorization, encryption, and secure coding practices.
  • Proficiency in threat modelling methodologies and tools to identify and assess potential security threats and vulnerabilities in software and systems.
  • Deep interest in application specific vulnerabilities, infrastructure knowledge.
  • Experience in collecting, analysing, and interpreting qualitative and quantitative data from defined application security services related sources (tools, monitoring techniques etc.)
  • In-depth knowledge of security architecture design and best practices, including secure design patterns, access control, and data protection
  • Knowledge of cloud security frameworks (e.g., AWS Well-Architected Framework, Azure Security Benchmark) to assess and improve security measures.
  • Familiarity with security standards and frameworks, such as OWASP Top Ten, NIST Cybersecurity Framework, ISO 27001, and CIS Controls.
  • Ability to conduct risk assessments to evaluate the potential impact and likelihood of security risks and provide risk mitigation strategies.
  • Familiarity with security testing tools like vulnerability scanners, penetration testing tools, and code analysis tools.
  • Understanding of network and system architecture, protocols, and configurations to assess security at the infrastructure level.
  • Understanding of industry-specific regulations, compliance requirements, and security challenges relevant to the organization's sector (e.g., healthcare, finance, or government).
  • Awareness of the current threat landscape, emerging security threats, and attack vectors.
  • Familiarity with software development methodologies (e.g., Agile, Dev Ops) to integrate security into the development process.
  • Experience with performing application threat modelling using tools and manual techniques
  • Understanding of leading vulnerability scoring standards, such as CVSS, and ability to translate vulnerability severity as security risk.
  • Knowledge of cloud environments and deployment solutions such as server less computing.
  • Possession of excellent oral and written communication skill.
Qualifications

  • 3+ years of related job experience
  • Comprehensive technical expertise in a variety of Dev Sec Ops toolkits, including Ansible, Jenkins, Artifactory, Jira, Terraform, Git/Version Control Software, or comparable technologies.
  • Familiarity with information security frameworks and standards such as PCI-DSS, HIPPA, NIST, GDPR, CIS, and OWASP Top 10.
  • Knowledge of Dev Ops Automation (Terraform, Helm, Git Hub, Git Hub Actions)
  • Knowledge of K8s, Linux, SIEM, and SOC or similar services
  • Knowledge of cloud platforms Azure, AWS, and Google Cloud.
  • Familiarity with API Security, Application Security, Container Security, and Cloud Security
  • Good knowledge of Logging, Monitoring, and Security tools such as ELK Stack, Prometheus, and Grafana.
  • Knowledge of databases such as My SQL, Postgre SQL, Mongo DB, and Redis
  • Familiarity with CNAPP tools and managing the Compliance Scanning, Runtime Container Security and Policy Configurations.


  • Bengaluru, Karnataka, India CyRAACS™ Full time

    The ideal candidate will be responsible for maintaining product and industry knowledge. You will work in a team-oriented environment that accelerates operational efficiency. Responsibilities • Work along with the Development/DevOps team to integrate application security tools in CI/CD pipeline. • To understand the supply chain attack in SDLC and...


  • Bengaluru, Karnataka, India Brillio Full time

    We are hiring for Threat Modelling Specialist Exp level: 6 to 10 Years location: Bangalore Preferred immediate to 30 days joiners Shift: Rotational shift Mode: Hybrid JD: The Threat Modeling Specialist is responsible for identifying, analyzing, and mitigating potential security threats to the organization's systems and applications. This role...


  • Bengaluru, Karnataka, India Standard Chartered Bank Full time

    RESPONSIBILITIESPartner with stakeholders to learn and understand a wide variety of threat model subjectsResponsible for building cyber threat models following the defined standardsResponsible for writing and maintaining the documentation relating threat models and technical architecture of analyzed systemsResponsible to execute cyber-attack simulations...


  • Bengaluru, Karnataka, India timesjobs Full time

    # DevSecOps## SaaS Engineering Engineering - India Bangalore, India### ReqNum:26774Hungry, Humble, Honest, with Heart.### The OpportunityWe are seeking an experienced and highly skilled Senior DevSecOps Professional to lead our DevSecOps initiatives and drive the implementation of security best practices across our organization. As a Senior DevSecOps...


  • Bengaluru, Karnataka, India timesjobs Full time

    # DevSecOps## SaaS Engineering Engineering - India Bangalore, India### ReqNum:26774Hungry, Humble, Honest, with Heart.### The OpportunityWe are seeking an experienced and highly skilled Senior DevSecOps Professional to lead our DevSecOps initiatives and drive the implementation of security best practices across our organization. As a Senior DevSecOps...


  • Bengaluru, Karnataka, India Nutanix Full time

    Hungry, Humble, Honest, with Heart.The OpportunityWe are seeking an experienced and highly skilled Senior DevSecOps Professional to lead our DevSecOps initiatives and drive the implementation of security best practices across our organization. As a Senior DevSecOps Professional, you will be responsible for architecting, implementing, and maintaining secure,...


  • Bengaluru, Karnataka, India Nutanix Full time

    Hungry, Humble, Honest, with Heart.The OpportunityWe are seeking an experienced and highly skilled Senior DevSecOps Professional to lead our DevSecOps initiatives and drive the implementation of security best practices across our organization. As a Senior DevSecOps Professional, you will be responsible for architecting, implementing, and maintaining secure,...

  • Devsecops Architect

    2 weeks ago


    Bengaluru, Karnataka, India Wipro Limited Full time

    Overview:Role PurposeAs an Enterprise DevOps / DevSecOps Architect, you will be involvedin a combination of strategizing & designing transformationroadmaps, facilitation, mentoring, coaching and training teams to enableDevOps / DevSecOps adoption at scale. You needs to examine and analyzethe client's development operations, define a robust DevOps /DevSecOps...


  • Bengaluru, Karnataka, India Western Digital Full time

    Company Description Western Digital's reliance on software development workflows is growing by leaps and bounds as a leading provider of Storage Solutions. As Secure Development Factory (SDF) Senior Infrastructure Engineer, you will be at the heart of Western Digital's engineering process, delivering the software development tools and infrastructure...

  • Threat Hunter

    2 weeks ago


    Bengaluru, Karnataka, India Cyble Inc. Full time

    About the Role:The Cyber Threat Hunter will have an opportunity to lead threat hunting missions to support our global research and client threat intelligence teams.He/She will track emerging threats and threat actors and Advanced Persistent Threat groups, evaluate, and prioritize threat artifacts (malware samples, IOCs, IOAs) and conduct a deeper analysis....

  • DevSecOps Engineer

    2 weeks ago


    Bengaluru, Karnataka, India Autodesk Full time

    Position OverviewWe are looking for a DevSecOps Engineer to help to further secure our customer data, applications, and infrastructure at Autodesk. This person will actively collaborate with team members and the wider Autodesk engineering community in producing quality deliverables in an efficient manner. This person will understand the AWS security...

  • Threat Hunter

    2 weeks ago


    Bengaluru, Karnataka, India Cyble Inc. Full time

    About the Role:The Cyber Threat Hunter will have an opportunity to lead threat hunting missions to support our global research and client threat intelligence teams.He/She will track emerging threats and threat actors and Advanced Persistent Threat groups, evaluate, and prioritize threat artifacts (malware samples, IOCs, IOAs) and conduct a deeper analysis....

  • DevSecOps Engineer

    2 weeks ago


    Bengaluru, Karnataka, India Dimiour Full time

    Role Description :Work within a remotely distributed DevSecOps team to plan and build a DevSecOps Platform as a Product for the self-service automation of Azure Cloud-Native infrastructure build & deployments.Key Responsibilities and Expectations : Build automation of Infrastructure and workloads for build, test, and deploy for optimal performance and...

  • Devsecops Engineer

    2 weeks ago


    Bengaluru, Karnataka, India Encora Inc. Full time

    Important Information Experience: 5 to 8 years Job Location: Bangalore Position Type: Full time. Work Mode- Hybrid Role: DevSecops Engineer Job Summary: Mandatory skills Python – advanced know cmake – Intermediate to Advanced Windows, Linux OS knowledge – both OS knowledge is important Git (mandate), Bitbucket (desired)...

  • DevOps & DevSecOps

    2 weeks ago


    Bengaluru, Karnataka, India CIEL HR Services Full time

    Hi,P3 Position: Application Security – DevSecOps & DevOpsPrimary Skills10+Proficient in DevOps implementation and integration.Expert in building processes, implementation and integrating tools in CICD environment .Good Knowledge of DevSecOps (Secure CI/CD integration)Good knowledge of OWASP Top 10Expert in custom integration between Synopsis and...

  • DevSecOps Engineer

    2 weeks ago


    Bengaluru, Karnataka, India Domnic Lewis International Full time

    Scope of Position : The DevSecOps Engineer is a strategic role that underpins the operationalization of the global technology and process enablement strategy. This individual plays a multifaceted role encompassing the devel-opment of security guidelines, collaboration with diverse stakeholders, and fostering a SecDevOps community within the organizationWork...


  • Bengaluru, Karnataka, India The Cigna Group Full time

    Salesforce DevSecOps EngineerWe are looking for passionate Trailblazers to join our Technology team supporting Cigna healthcare International Markets' Salesforce organisations.Salesforce DevSecOps Engineers are the core of our Salesforce Platform team, responsible for making sure we get the most value from our Salesforce DevSecOps tools, improving Salesforce...

  • DevSecOps Engineer

    2 weeks ago


    Bengaluru, Karnataka, India Manpower Group Full time

    Qualifications :Bachelor's degree in Computer Science, Information Technology, or a related field. 2. 2-3 of experience in DevSecOps. Strong understanding of DevSecOps principles and practices. Knowledge of security tools and technologies, such as vulnerability scanners, intrusion detection systems, and ELK stack. Experience with cloud platforms (e.g., AWS,...

  • DevSecOps Engineer

    2 weeks ago


    Bengaluru, Karnataka, India Unisys Full time

    What success looks like in this role: Responsibilities 1Analyzing, Building Processes, Executing, and streamlining DevsecOps practices 2Automating processes with the right tools 3Develop best in class Runbooks for Devsecops for our Field Delivery as well as Facilitatinginternal development process and operations 4Establishing a suitable...


  • Bengaluru, Karnataka, India Varite India Full time

    Job Title : Application Security Engineer/DevSecOps Specialist.Location State : Telangana,Karnataka,Tamil Nadu.Location City : Hyderabad, Bengaluru,Chennai. Experience Required : 5 to 16 Year(s).Shift : Day Shift.Work Mode : Hybrid.Position Type : Contract.Openings : 5.Company Name : VARITE INDIA PRIVATE LIMITED.About The Client : A global information...