DevSecOps & Application Security Engineer
Role Summary: Experienced security practitioner focused on DevSecOps, application security, and cloud security architecture, supporting a banking/financial services client’s secure SDLC, infrastructure-as-code, supply-chain security, and privileged access / PKI controls.
Key Responsibilities: Design, develop, and review Terraform (IaC) with a security-first approach; perform IaC code reviews Architect and implement deep technical security controls across AWS and Microsoft (Azure / Microsoft security) environments Embed application security practices across design and delivery Implement policy-as-code enforcement across the SDLC — PR-time, pipeline-time, deploy-time, and runtime Drive supply-chain security: signed builds (Sigstore/cosign), SBOM generation, SLSA-aligned provenance, dependency pinning, runner isolation Set up and operationalize Veracode and/or GitHub Advanced Security Deploy and support CyberArk PAM and PKI Contribute to security runbooks, pipeline standards, and process documentation Support audit and compliance evidence gathering Escalate and coordinate on critical security events with senior leadership
Required Experience: 7+ years in cybersecurity operations/engineering, cloud security, or DevSecOps Hands-on Terraform coding and IaC code review experience Deep technical AWS and Microsoft security and architecture experience Application security experience
History of setting up Veracode and/or GitHub Advanced Security CyberArk PAM and PKI deployment experience BFSI or other regulated-industry experience preferred
Core Technical Expertise: Terraform / infrastructure-as-code security and code review AWS security architecture; Microsoft Azure / Microsoft security architecture DevSecOps toolchains and secure SDLC integration Application security (SAST/DAST/SCA in practice) Policy-as-code across PR, pipeline, deploy, and runtime Supply-chain security: Sigstore/cosign, SBOM, SLSA-aligned provenance, dependency pinning, runner isolation CyberArk PAM (deployment); PKI (deployment) Veracode and/or GitHub Advanced Security
Preferred Certifications AWS Certified Security – Specialty; Microsoft security/architecture certifications (e.g., AZ-500, SC-100, or equivalent) as applicable