Search

Lead Security Test Engineer - DevSecOps

Real Estate

Job Description

Job Title: Lead Security Test Engineer – DevSecOps

\n

Location: Englewood Cliffs, NJ (Hybrid)

\n

Job Type: Contract

\n


\n

Experience: 12+ Years

\n

Interview Requirement: Final round will be conducted in person. NJ local candidates are preferred.

\n


\n

Job Summary

\n

We are looking for a Lead Security Test Engineer with strong DevSecOps and Application Security experience to design, implement, and execute security testing throughout the software development lifecycle.

\n

The ideal candidate will have hands-on experience with SAST, DAST, SCA, API Security, Penetration Testing, Vulnerability Assessment, and Threat Modeling, along with the ability to integrate security testing into CI/CD pipelines.

\n

Key Responsibilities

\n

    \n
  • Design and execute security testing strategies for web applications, APIs, microservices, mobile applications, and cloud environments.
  • \n

  • Perform SAST, DAST, SCA, API security, container security, and infrastructure security testing.
  • \n

  • Conduct vulnerability assessments and penetration testing and validate remediation.
  • \n

  • Integrate security testing tools and automated security gates into CI/CD pipelines.
  • \n

  • Develop security testing automation using Python, Java, JavaScript, or Bash.
  • \n

  • Collaborate with Development, QA, DevOps, Cloud, and Security teams to identify and remediate vulnerabilities early.
  • \n

  • Implement shift-left security and DevSecOps controls across the SDLC.
  • \n

  • Configure and manage security tools for SAST, DAST, SCA, secrets scanning, container scanning, and IaC security.
  • \n

  • Perform security testing of Docker/Kubernetes environments.
  • \n

  • Test REST and GraphQL APIs, including authentication and authorization mechanisms.
  • \n

  • Integrate security checks with Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, or similar tools.
  • \n

  • Analyze vulnerability findings, prioritize risks, and track remediation through closure.
  • \n

  • Develop security test cases, automation frameworks, reports, and security metrics.
  • \n

  • Participate in threat modeling and security architecture reviews.
  • \n

  • Support security and compliance standards including OWASP Top 10, OWASP ASVS, SANS, NIST, and CIS Controls.
  • \n

  • Stay current with emerging security threats, testing methodologies, and DevSecOps tools.
  • \n

\n

Mandatory Skills

\n

    \n
  • Application Security Testing
  • \n

  • SAST
  • \n

  • DAST
  • \n

  • SCA
  • \n

  • API Security Testing
  • \n

  • Penetration Testing
  • \n

  • Vulnerability Assessment
  • \n

  • Threat Modeling
  • \n

  • OWASP
  • \n

  • DevSecOps
  • \n

  • Security Test Automation
  • \n

  • CI/CD Security Integration
  • \n

\n

Desirable Skills

\n

    \n
  • AWS Secrets Manager
  • \n

  • AWS / Cloud Security
  • \n

  • Docker / Kubernetes Security
  • \n

  • REST / GraphQL API Security
  • \n

  • Jenkins / GitHub Actions / GitLab CI/CD / Azure DevOps
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...