DevSecOps Security Analyst
New
BrazilFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Required Skills
- CI/CDAzure DevOps
Requirements
- Solid experience in Application Security and DevSecOps practices.
- Hands-on experience identifying and managing vulnerabilities in source code.
- Experience with security tools such as SAST, DAST, and SCA.
- Practical knowledge of Azure DevOps and security integration in CI/CD pipelines.
- Experience with threat modeling and definition of security requirements.
- Strong understanding of OWASP frameworks (ASVS, SAMM, WSTG, MASVS).
- Experience with secure code review and secure software development lifecycle practices.
- Ability to act in a consultative role, supporting development teams with security best practices.
- Experience with vulnerability governance and tracking in enterprise environments.
- Prior experience as a Security Champion or security advocate within engineering teams.
- Familiarity with cloud environments and secure architecture principles.
- Knowledge of security automation and continuous security improvement practices.
Responsibilities
- Identify vulnerabilities in source code and support the definition and tracking of remediation plans.
- Monitor and enhance secure coding practices across development teams and pipelines.
- Analyze and interpret results from SAST, DAST, and SCA security tools, ensuring proper remediation actions.
- Perform threat modeling and define security requirements aligned with application architecture and development standards.
- Support developers in fixing vulnerabilities and implementing security guardrails throughout the SDLC.
- Contribute to governance processes for vulnerability management across code, architecture, and applications.
- Integrate and monitor security practices within CI/CD pipelines using Azure DevOps.
- Promote security awareness through training sessions, guidance, and Security Champion activities.
- Collaborate closely with development, architecture, operations, and security teams to ensure secure delivery.
- Support automation initiatives for security testing and vulnerability management.
View Full Description & ApplyYou'll be redirected to the employer's site