Tredence Inc.
Website:
tredence.com
Job details:
Role description
Job Description – Consultant, DevSecOps & Validation
Location: Bangalore
Department: Information Security Group (ISG)
Role: Consultant – DevSecOps & Validation
Experience: 2-5 Years
Employment Type: Full-Time
About the Role
We are looking for a skilled and motivated Consultant – DevSecOps & Validation to strengthen our Secure Software Development Lifecycle (SSDLC) and Vulnerability Management program. The candidate will work closely with development, cloud, infrastructure, and security teams to identify, assess, and remediate security vulnerabilities across applications, cloud platforms, and CI/CD environments.
Key Responsibilities
- Implement and drive Secure SDLC and DevSecOps practices across the organization.
- Build, review, and troubleshoot CI/CD pipelines using Jenkins, GitHub Actions, GitLab, and Azure DevOps.
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, cloud, and AI applications.
- Integrate and manage security tools such as SAST, DAST, SCA, container scanning, and secret scanning.
- Monitor organizational vulnerability posture and coordinate remediation with stakeholders.
- Conduct security gap assessments and recommend security improvements.
- Review security exceptions and ensure compliance with organizational security standards.
- Stay updated on emerging cyber threats, vulnerabilities, and security best practices.
Required Skills
2-5 years of experience in Information Security, DevSecOps, or Application Security.
Strong understanding of:
- OWASP Top 10
- CVE/CVSS
- OWASP ASVS
- SANS Top 25
- MITRE ATT&CK Framework
- Cyber Kill Chain
Hands-on experience with:
- SAST, DAST, SCA, IAST
- Container Security & Vulnerability Management
- CI/CD Security
Experience with security tools such as:
- Qualys, Rapid7, Checkmarx, Veracode
- Snyk, Black Duck, Trivy, Semgrep
- OWASP ZAP, Burp Suite, GitGuardian
- Nessus, Nmap, Wireshark, Metasploit, Kali Linux
Scripting and automation knowledge in:
- Python
- Shell Scripting
- PowerShell
- JavaScript
- SQL
Preferred Qualifications
- Engineering degree in Computer Science, Information Technology, Cyber Security, or related field.
- Relevant certifications such as:
Key Competencies
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management skills.
- Self-driven, proactive, and detail-oriented.
- Passion for cybersecurity and continuous learning.
If you are passionate about Application Security, DevSecOps, and Vulnerability Management, and want to work in a fast-paced security-driven environment, we would love to hear from you.
Click on Apply to know more.