DevSecOps Security Analyst

New
BrazilFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Required Skills
CI/CDAzure DevOps

Requirements

  • Solid experience in Application Security and DevSecOps practices.
  • Hands-on experience identifying and managing vulnerabilities in source code.
  • Experience with security tools such as SAST, DAST, and SCA.
  • Practical knowledge of Azure DevOps and security integration in CI/CD pipelines.
  • Experience with threat modeling and definition of security requirements.
  • Strong understanding of OWASP frameworks (ASVS, SAMM, WSTG, MASVS).
  • Experience with secure code review and secure software development lifecycle practices.
  • Ability to act in a consultative role, supporting development teams with security best practices.
  • Experience with vulnerability governance and tracking in enterprise environments.
  • Prior experience as a Security Champion or security advocate within engineering teams.
  • Familiarity with cloud environments and secure architecture principles.
  • Knowledge of security automation and continuous security improvement practices.

Responsibilities

  • Identify vulnerabilities in source code and support the definition and tracking of remediation plans.
  • Monitor and enhance secure coding practices across development teams and pipelines.
  • Analyze and interpret results from SAST, DAST, and SCA security tools, ensuring proper remediation actions.
  • Perform threat modeling and define security requirements aligned with application architecture and development standards.
  • Support developers in fixing vulnerabilities and implementing security guardrails throughout the SDLC.
  • Contribute to governance processes for vulnerability management across code, architecture, and applications.
  • Integrate and monitor security practices within CI/CD pipelines using Azure DevOps.
  • Promote security awareness through training sessions, guidance, and Security Champion activities.
  • Collaborate closely with development, architecture, operations, and security teams to ensure secure delivery.
  • Support automation initiatives for security testing and vulnerability management.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now