Devsecops Lead Engineer

4 weeks ago


Nashik, India Zensar Technologies Full time

Summary: The role of an Application Security Engineer is integral to integrating security practices within our DevOps methodology, effectively bridging any gaps between IT and security while ensuring the swift and safe release of code. This role involves implementing security measures throughout the DevOps pipeline to protect applications and APIs, ensuring compliance with necessary security standards. Key Responsibilities: - Incorporate security measures into every stage of the DevOps pipeline to protect applications and APIs. - Implement and maintain controls within the Continuous Integration/Continuous Deployment (CI/CD) pipeline to meet necessary security standards. - Gain experience with SAST (Static Application Security Testing), SCA (Software Composition Analysis), DAST (Dynamic Application Security Testing), IaC (Infrastructure as Code) security, Container security, integrating security in IDEs (Integrated Development Environments), and API security. - Regular usage of automated tools for routine security checks. - Facilitate collaboration among development, operations, and security teams. - Develop policies that align with regulations, alongside conducting comprehensive assessments of application/API security. - Educate teams about secure application/API usage, keeping up-to-date with cybersecurity trends, ensuring adherence to secure design principles across all Software Development Life Cycle (SDLC) phases, managing incident response protocols, and providing training on secure coding best practices. - Utilize automation tools to identify potential vulnerabilities before they escalate into threats. - Evaluate third-party services for potential weaknesses in their security posture. - Proficiency in scripting languages such as Python and familiarity with common programming languages. - Empower developers with hands-on practices in secure coding. Additional duties include ensuring that vulnerabilities are remediated before code moves to production and providing guidance on the remediation process for application/API security vulnerabilities. This role also requires collaboration with Information Security Officers (ISOs), DevOps teams, Application Development teams, Vendor Partners, and Cyber Engineering teams. The position ensures compliance with industry-specific regulations such as GDPR or HIPAA. EXPERIENCE AND EDUCATIONAL REQUIREMENTS: - Bachelor's degree in IT, Cybersecurity, or a related field, or equivalent work experience. - Security certifications such as CISSP (Certified Information Systems Security Professional), OSCP (Offensive Security Certified Professional), or CEH (Certified Ethical Hacker) would be advantageous. - Minimum 5 years of experience in a similar role within a large, geographically dispersed environment. - Strong understanding of information security principles. - Excellent communication skills: able to explain complex concepts clearly to both technical and non-technical stakeholders. - Understanding of industry-standard regulations, risk management, and security controls frameworks and standards (e.g., ISO, PCI, NIST, GAPP, HIPAA, GDPR, CIS, SANS, OWASP Top 10, MITRE ATT&CK, etc.). Skills Desired: - Understanding of risk assessment methodologies. - Experience with various vulnerability assessment tools (e.g., Checkmarx, Microsoft Defender). - Strong interpersonal skills: ability to work collaboratively within a team. - Reporting and metrics expertise with platforms such as ServiceNow (SecOps), PowerBI, etc.


  • DevSecOps Engineer

    4 weeks ago


    Nashik, India Maxima Consulting Full time

    About the project: We're seeking an experienced DevSecOps Engineer to take ownership of our Client's Internal Developer Platform (IDP) based on Port.io. In this role, you'll empower engineering teams through self-service capabilities, standardized deployment templates, automation, and built-in security practices. You'll be at the intersection of development,...


  • Nashik, India inventurus knowledge soln Full time

    About the Role:We are seeking a highly experienced and hands-on DevOps Subject Matter Expert (SME) with deep specialization in Google Cloud Platform (GCP) and a proven track record in designing and implementing CI/CD pipelines, cloud-native architectures, MLOps frameworks, and DevSecOps practices. The ideal candidate will bring a strong foundation in cloud...

  • Devsecops Engineer

    2 weeks ago


    Nashik, Pune, India Winjit Technologies Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Key ResponsibilitiesSecurity Integration: Design, implement, and manage security controls and automation within CI/CD pipelines (e.g., Jenkins, GitLab CI/CD, Azure DevOps).Vulnerability Management: Conduct static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) to identify, evaluate,...


  • Nashik, India NuStudio.AI Full time

    We’re Hiring: Product Engineering Lead (8–10 Years Experience; Hyderabad, IN)   At Nu Studio.ai, we’re building the next generation of AI-powered products — intelligent platforms, digital assistants, and immersive enterprise apps that bring data, design, and AI together.   We’re looking for engineers to architect and drive the engineering behind...


  • Nashik, India Jio Full time

    Role Overview We are seeking an experienced Electrical Engineering Lead to head the design and engineering function for large-scale EPC projects in mission-critical and high-technology environments such as data centers. The ideal candidate will bring deep expertise in electrical systems design, strong leadership skills, and a proven ability to deliver...

  • Lead Engineer

    2 days ago


    Nashik, Maharashtra, India EPIROC Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Description- Lead Engineer - PurchaseJob MissionThis position will be responsible for coordinating with key suppliers and managing Powertrain / hydraulic commodities. The role includes monitoring supplier KPIs such as delivery precision, lead time performance, and lead time accuracy. The incumbent will ensure uninterrupted supply by providing accurate...


  • Nashik, India Emerson Full time

    In This Role, Your Responsibilities Will Be: Implement to Emerson's project execution life cycle and maintain all relevant documentation, including technical and quality documents. Own the project and act as the primary connect with the customer for the entire scope of the project. Provide technical support to the Project Manager, assisting with activities...


  • Nashik, India Mizuho Full time

    Mizuho Global Services Pvt Ltd (MGS) is a subsidiary company of Mizuho Bank, Ltd, which is one of the largest banks or so called ‘Mega Banks’ of Japan. MGS was established in the year 2020 as part of Mizuho’s long-term strategy of creating a captive global processing center for remotely handling banking and IT related operations of Mizuho Bank’s...


  • Nashik, India Sequoia Consulting Group Full time

    About Sequoia Consulting GroupSequoia Consulting Group is a tech-enabled consulting and services company that provides benefits, HR, payroll, and risk management solutions for people-centric employers with 20 to 20,000 people. The Sequoia People Platform centralizes workforce data and helps companies navigate complex issues so they can maximize their...


  • Nashik, India L&T Technology Services Full time

    About us: L&T Technology Services Limited (LTTS) is a global leader in Engineering and R&D (ER&D) services. With 816 patents filed for 57 of the Global Top 100 ER&D spenders, LTTS lives and breathes engineering and technology. Our innovations speak for themselves – World’s 1st Autonomous Welding Robot, Solar ‘Connectivity’ Drone, and the Smartest...