DevSecOps Specialist

Interested suitable candidates please be in touch with roopashree.ry@sutherlandglobal.com

Job Title: Lead Security Engineer / DevSecOps Specialist

Department: Information Security & Engineering

Employment Type: Full-Time

Role Overview

We are seeking an experienced and hands-on Security Professional to bridge the gap between software development, cloud operations, and enterprise security governance. In this role, you will embed security into every stage of the Software Development Life Cycle (SDLC)from initial architectural design to deployment and hosting. You will drive our DevSecOps program while conducting rigorous security reviews, vulnerability assessments, and compliance audits against industry standards.

Key Responsibilities

  • DevSecOps Implementation & CI/CD Security: Build, maintain, and integrate automated security testing tools (SAST, DAST, SCA, IAST, container scanning) directly into continuous integration and deployment pipelines.
  • Architecture & Design Reviews: Conduct threat modeling, risk assessments, and architectural security reviews for new applications, microservices, and cloud deployments prior to development.
  • Security Audits & Assessments: Perform regular code audits, vulnerability assessments, and end-to-end security evaluations across web, mobile, API, and cloud infrastructure platforms.
  • Compliance & Governance: Ensure application and infrastructure configurations comply with key security standards (OWASP Top 10, ISO 27001, NIST SP 800-53, CIS Benchmarks, SOC 2, PCI-DSS).
  • Secure Hosting & Cloud Security: Audit and harden cloud infrastructure (AWS/Azure/GCP), container environments (Docker, Kubernetes), and hosting configurations.
  • Remediation & Mentorship: Partner closely with engineering teams to provide clear remediation guidance for identified vulnerabilities and foster a security-first engineering culture.
Required Skills & Qualifications
  • Hands-on DevSecOps: 3+ years of experience integrating security tools (e.g., Snyk, SonarQube, Checkmarx, Trivy, Zap, Semgrep) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins).
  • Application Security (AppSec): Deep understanding of common application vulnerabilities (OWASP), secure coding principles, and hands-on experience performing manual and automated source code reviews.
  • General Security Breadth: Broad knowledge spanning network security, identity and access management (IAM), cryptography, endpoint security, and incident response fundamentals.
  • Standards & Audit Expertise: Strong familiarity with frameworks such as ISO 27001, NIST, CIS, SOC 2, and PCI-DSS, with proven experience conducting formal gap analyses and compliance audits.
  • Cloud & Container Infrastructure: Experience securing cloud-native workloads, Infrastructure as Code (Terraform, CloudFormation), and container orchestration technologies.
  • Experience in fixes or recommending fixes for identified vulnerabilities
  • Experience and usage on Cycode is added advantage.
Preferred Qualifications & Certifications
  • Certifications: CISSP, CISA, CEH, GWAPT, OSWE, CSSLP, or AWS/Azure Security Specialty.
  • Strong scripting/programming capabilities (Python, Bash, Go, or JavaScript) for automation.
  • Experience communicating risk effectively to both technical developers and business executives.
Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...