· CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins
· Container scanning: Trivy, Grype, or equivalent
· IaC scanning: Checkov, tfsec, or equivalent
· Scripting for automation: Python, Bash, or YAML-based pipeline configuration
These are non-negotiable. If you do not meet all of these, this role is not the right fit.
· 5+ years of experience managing DevSecOps or application security testing platforms in a production environment
· Hands-on expertise with at least 2 of: Checkmarx, SonarQube, Snyk, Veracode, Fortify, or equivalent SAST/SCA platforms
· Experience integrating security scanning into CI/CD pipelines — GitHub Actions, Azure DevOps, Jenkins, or GitLab CI
· Strong understanding of DAST tools and web application scanning (Qualys WAS, OWASP ZAP, Burp Suite Enterprise, or equivalent)
· Ability to tune scan policies, write custom rules, and reduce false positive rates — this is a core competency, not a nice-to-have
· Working knowledge of container security scanning (Trivy, Grype, or equivalent) and IaC scanning (Checkov, tfsec, or equivalent)
· Clear communication skills for working with developers who may not have security backgrounds