Specialist

September 22, 2026
Application ends: December 21, 2026
Apply Now

Job Description

Responsibilities

  • DevSecOps Implementation & CI/CD Security: Build, maintain, and integrate automated security testing tools (SAST, DAST, SCA, IAST, container scanning) directly into continuous integration and deployment pipelines.
  • Architecture & Design Reviews: Conduct threat modeling, risk assessments, and architectural security reviews for new applications, microservices, and cloud deployments prior to development.
  • Security Audits & Assessments: Perform regular code audits, vulnerability assessments, and end-to-end security evaluations across web, mobile, API, and cloud infrastructure platforms.
  • Compliance & Governance: Ensure application and infrastructure configurations comply with key security standards (OWASP Top 10, ISO 27001, NIST SP 800-53, CIS Benchmarks, SOC 2, PCI-DSS).
  • Secure Hosting & Cloud Security: Audit and harden cloud infrastructure (AWS/Azure/GCP), container environments (Docker, Kubernetes), and hosting configurations.
  • Remediation & Mentorship: Partner closely with engineering teams to provide clear remediation guidance for identified vulnerabilities and foster a security-first engineering culture.

Required Skills & Qualifications

  • Hands-on DevSecOps: 3+ years of experience integrating security tools (e.g., Snyk, SonarQube, Checkmarx, Trivy, Zap, Semgrep) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins).
  • Application Security (AppSec): Deep understanding of common application vulnerabilities (OWASP), secure coding principles, and hands-on experience performing manual and automated source code reviews.
  • General Security Breadth: Broad knowledge spanning network security, identity and access management (IAM), cryptography, endpoint security, and incident response fundamentals.
  • Standards & Audit Expertise: Strong familiarity with frameworks such as ISO 27001, NIST, CIS, SOC 2, and PCI-DSS, with proven experience conducting formal gap analyses and compliance audits.
  • Cloud & Container Infrastructure: Experience securing cloud-native workloads, Infrastructure as Code (Terraform, CloudFormation), and container orchestration technologies.
  • Experience in fixes or recommending fixes for identified vulnerabilities
  • Experience and usage on Cycode is added advantage.

Preferred Qualifications & Certifications

  • Certifications: CISSP, CISA, CEH, GWAPT, OSWE, CSSLP, or AWS/Azure Security Specialty.
  • Strong scripting/programming capabilities (Python, Bash, Go, or JavaScript) for automation.
  • Experience communicating risk effectively to both technical developers and business executives

Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#GraphicDesignJobsOnline
#WebDesignRemoteJobs
#FreelanceGraphicDesigner
#WorkFromHomeDesignJobs
#OnlineWebDesignWork
#RemoteDesignOpportunities
#HireGraphicDesigners
#DigitalDesignCareers
# Dynamicbrand guru