Role Description: The Application Security / DevSecOps Engineer will support the client’s enterprise Application Security program by integrating security controls and scanning capabilities throughout the software development lifecycle and CI/CD pipelines. The resource will work across multiple source code management and DevOps platforms, including GitHub, GitLab, Azure DevOps (ADO), and Jenkins, and will be responsible for onboarding applications into security scanning solutions such as Checkmarx. Responsibilities include configuring and executing SAST and SCA scans, establishing recurring scanning schedules, reviewing and analyzing scan results, supporting remediation of identified vulnerabilities, and integrating security findings with the appropriate development and security workflows. The resource should also provide hands-on application security expertise beyond automated tooling, including secure code review, identification of coding and validation weaknesses, review of third-party and open-source libraries/packages, and assessment of software supply-chain risks. The individual will work closely with application and development teams to identify security gaps, provide remediation guidance, and help ensure that applications consume trusted and secure software components
Since 1996, RJT has provided successful SAP, Oracle, and IT consulting solutions and staffing services to clients around the world. The new Apolis brings you the same personalized service fortified with a greater array of IT solutions, global expertise, and cost-management strategies.
We are a global IT consultancy that seamlessly integrates experts and leading-edge solutions into your organization so you can focus on what really matters.