"The right candidate will have total 9 to 12 years of experience in software development design & development / coding and engineering practices along with extensive experience in DevSecOps and product secure development lifecycle (Secure SDL) and methodologies implementation & governance.
Good knowledge of infrastructure as code, end-to-end fully-automated CI / CD pipelines, from code commits to production and security of repositories (like GitHub, BitBucket etc), pipelines, build / release tools (like Jenkins, GitHub actions etc) and methodologies in CI / CD pipelines.
Proficiency in scripting, including Python, Groovy, Helm, shell scripts, Perl etc to support the automation and continuous improvement of processes
Hands on experience in DevSecOps, Secure SDLC including Threat Modeling, Vulnerability assessment. Security Testing, Security Scans and Security compliance like PCI-DSS / GDPR / ISO. Exposure on Webservices( SOAP / REST) security assessment will be a definite plus
Experience in full DevSecOps CI / CD pipeline, Agile methodology, container security, APIs, and microservices.
Knowledge of OWASP Top10, SANS Top25, CWE and CVE / Mitre, along with hands-on practical experience in development & testing for vulnerabilities and implementing remediation."
Information Security Specialist • Bengaluru, Karnataka, India