…

Information Security Engineer

Tredence · IT Services & Consulting

  • Bangalore
  • On-site
  • Posted yesterday
  • Cybersecurity

About the job

Job Description – Consultant, DevSecOps & Validation

Location: Bangalore

Department: Information Security Group (ISG)

Role: Consultant – DevSecOps & Validation

Experience: 2-5 Years

Employment Type: Full-Time

About the Role

We are looking for a skilled and motivated Consultant – DevSecOps & Validation to strengthen our Secure Software Development Lifecycle (SSDLC) and Vulnerability Management program. The candidate will work closely with development, cloud, infrastructure, and security teams to identify, assess, and remediate security vulnerabilities across applications, cloud platforms, and CI/CD environments.

Key Responsibilities

Implement and drive Secure SDLC and DevSecOps practices across the organization.
Build, review, and troubleshoot CI/CD pipelines using Jenkins, GitHub Actions, GitLab, and Azure DevOps.
Perform Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, cloud, and AI applications.
Integrate and manage security tools such as SAST, DAST, SCA, container scanning, and secret scanning.
Monitor organizational vulnerability posture and coordinate remediation with stakeholders.
Conduct security gap assessments and recommend security improvements.
Review security exceptions and ensure compliance with organizational security standards.
Stay updated on emerging cyber threats, vulnerabilities, and security best practices.

Required Skills

-

2-5 years of experience in Information Security, DevSecOps, or Application Security.

-

Strong understanding of:

OWASP Top 10
CVE/CVSS
OWASP ASVS
SANS Top 25
MITRE ATT&CK Framework
Cyber Kill Chain

-

Hands-on experience with:

SAST, DAST, SCA, IAST
Container Security & Vulnerability Management
CI/CD Security

-

Experience with security tools such as:

Qualys, Rapid7, Checkmarx, Veracode
Snyk, Black Duck, Trivy, Semgrep
OWASP ZAP, Burp Suite, GitGuardian
Nessus, Nmap, Wireshark, Metasploit, Kali Linux

-

Scripting and automation knowledge in:

Python
Shell Scripting
PowerShell
JavaScript
SQL

Preferred Qualifications

Engineering degree in Computer Science, Information Technology, Cyber Security, or related field.
Relevant certifications such as:
OSCP
CEH
eJPT
Security+

Key Competencies

Strong analytical and problem-solving skills.
Excellent communication and stakeholder management skills.
Self-driven, proactive, and detail-oriented.
Passion for cybersecurity and continuous learning.

If you are passionate about Application Security, DevSecOps, and Vulnerability Management, and want to work in a fast-paced security-driven environment, we would love to hear from you.