93 open roles
Application Security (AppSec) / DevSecOps Engineer
Job description
This is a remote position. Application Security (App. Sec) / Dev. Sec. Ops Engineer Job Details Employment Type: Contract Work Mode: Remote Location: Offshore Total Experience Required: 4 to 8 years Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering Dev.
Sec. Ops pipelines Mandatory Certification: Certified Application Security Engineer (CASE), Certified Dev. Sec. Ops Professional (CDP), CSSLP, or CEH Job Summary We are seeking an experienced Application Security / Dev. Sec. Ops Engineer to bake robust safety controls directly into our automated software delivery frameworks.
The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.
Key Responsibilities
Design and integrate automated security testing gates directly into modern CI/CD pipelines (e.g., GitHub Actions , GitLab CI , Jenkins ). Configure and manage application scanning frameworks , orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
Triage and remediate software vulnerabilities , analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams. Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
Govern application security infrastructure , managing centralized vulnerability aggregation dashboards (e.g., Defect. Dojo , Sonar. Qube ) and secret vaults (e.g., Hashi. Corp Vault , AWS Secrets Manager ). Secure containerized application workloads , auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
Drive application layer incident investigations , analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.
Requirements
4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks. Strong technical mastery of automated testing engines (e.g., Snyk , Checkmarx , Veracode, OWASP ZAP ), container security paradigms, and infrastructure-as-code hardening.
Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols. Mandatory certification: CASE, CDP, CSSLP, or CEH.
Preferred Qualifications
Prior experience with software development in languages like Java, Python, JavaScript/Node.js, or Go . Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.
Description copied from FyerX's careers page. Read the full posting before you apply.
More jobs at FyerX
ServiceNow Tech Lead
FyerXServiceNow Developer (ITSM, ITOM, CMDB & HAM)
FyerX· Bangalore South, IndiaWorkday Extend Developer
FyerXSalesforce Certified Agentforce / AI Specialist
FyerXServiceNow Certified Technical Architect (CTA)
FyerX