Job description:
The DevSecOps Engineer will be responsible for automating security processes, like vulnerability management. The role involves integrating security tools and implementing processes into the development lifecycle, ensuring continuous security testing, and feeding results back to developers.
Key responsibilities include:
- Implementing into projects security tools such as SAST, secret scanning, and security testing report generation.
- Developing and maintaining CI/CD pipelines using tools like TeamCity, Jenkins, and Azure DevOps.
- Generating and analyzing Software Bill of Materials (SBOM) and integrating with tools like Dependency Track and Defect Dojo.
- Integrating security scanners like Semgrep and gitleaks.
- Collaborating with development teams to provide vulnerability feedback and support them with analysis and resolution.
- Utilizing containerization and orchestration tools like Docker and Kubernetes.
- Writing scripts and automation using Bash, Python, and PowerShell.