Quick Overview
Job Description
Job Title : Lead Security Test Engineer – DevSecOps
Location: Englewood Cliffs, NJ (Hybrid )
Job Type : Contract
Experience: 10+ Years
Interview Requirement: Final round will be conducted in person. NJ local candidates are preferred.
Job Summary
We are looking for a Lead Security Test Engineer with strong DevSecOps and Application Security experience to design, implement, and execute security testing throughout the software development lifecycle.
The ideal candidate will have hands-on experience with SAST, DAST, SCA, API Security, Penetration Testing, Vulnerability Assessment, and Threat Modeling, along with the ability to integrate security testing into CI/CD pipelines.
Key Responsibilities
- Design and execute security testing strategies for web applications, APIs, microservices, mobile applications, and cloud environments.
- Perform SAST, DAST, SCA, API security, container security, and infrastructure security testing.
- Conduct vulnerability assessments and penetration testing and validate remediation.
- Integrate security testing tools and automated security gates into CI/CD pipelines.
- Develop security testing automation using Python, Java, JavaScript, or Bash.
- Collaborate with Development, QA, DevOps, Cloud, and Security teams to identify and remediate vulnerabilities early.
- Implement shift-left security and DevSecOps controls across the SDLC.
- Configure and manage security tools for SAST, DAST, SCA, secrets scanning, container scanning, and IaC security.
- Perform security testing of Docker/Kubernetes environments.
- Test REST and GraphQL APIs, including authentication and authorization mechanisms.
- Integrate security checks with Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, or similar tools.
- Analyze vulnerability findings, prioritize risks, and track remediation through closure.
- Develop security test cases, automation frameworks, reports, and security metrics.
- Participate in threat modeling and security architecture reviews.
- Support security and compliance standards including OWASP Top 10, OWASP ASVS, SANS, NIST, and CIS Controls.
- Stay current with emerging security threats, testing methodologies, and DevSecOps tools.
Mandatory Skills
- Application Security Testing
- SAST
- DAST
- SCA
- API Security Testing
- Penetration Testing
- Vulnerability Assessment
- Threat Modeling
- OWASP
- DevSecOps
- Security Test Automation
- CI/CD Security Integration
Desirable Skills
- AWS Secrets Manager
- AWS / Cloud Security
- Docker / Kubernetes Security
- REST / GraphQL API Security
- Jenkins / GitHub Actions / GitLab CI/CD / Azure DevOps
Similar jobs
- AI
Senior Red Team Engineer, Discovery
NewAnduril Industries
Washington🇺🇸YesterdayMATLABMachine LearningNumPy+12Technology - AI
Senior Red Team Engineer, Discovery
NewAnduril Industries
Costa Mesa🇺🇸YesterdayMATLABMachine LearningNumPy+12Technology - 6S
Sr. Security Assurance Engineer
6sense
United States🇺🇸Remote3 days ago401kSQLAWS+16 - VS
Security Analyst II | W2/1099 Role | Applicant Must Be Current WI Resident
NewV.L.S. Systems, Inc
Madison, WI🇺🇸Remote21 hours agoTechnology - NI
Security Architect
NewNSD International, Inc.
Charlotte, NC🇺🇸Hybrid21 hours agoTechnology - TE
Network Security Engineer- W2 position only
NewTeknosys Inc
Atlanta, GA🇺🇸Hybrid21 hours agoAWSTCP/IPAzure+4Technology