Jobiglo

No results.

This job is no longer available

This job expired on 28/07/2026. It no longer accepts applications.

Secure Development Analyst (AppSec / DevSecOps)

EPAM Systems · Córdoba

🇬🇧 English
Jenkins Podman Veracode Checkmarx Snyk Semgrep GitLeaks SAST SCA DAST secret scanning IAST Bitbucket SonarQube JFrog Artifactory Docker Kubernetes OpenShift AWS Azure GCP Java Node.js JavaScript TypeScript Python Go .NET OIDC OAuth 2.0 SAML JWT mTLS Keycloak SSL/TLS PKI Vault STRIDE PASTA attack trees

Job description

About the role

We are seeking a Secure Development Analyst to strengthen our DevSecOps capabilities. You will enhance our CI/CD delivery by embedding automated security controls, ensuring the Jenkins + Podman ecosystem runs smoothly, and partnering with engineering teams to reduce risk.

Key responsibilities

  • Operate and evolve DevSecOps infrastructure supporting Veracode scans across Jenkins and Podman.
  • Maintain and improve CI/CD pipelines by adding automated SAST, SCA, DAST, secret scanning, and container image analysis controls.
  • Design security gates that balance risk reduction with developer velocity.
  • Integrate and maintain tooling connections with Bitbucket, SonarQube, and JFrog Artifactory.
  • Triage security findings, prioritize remediation, and guide teams through resolution.
  • Conduct early design and story reviews in agile delivery against defined security standards.
  • Collaborate with development and architecture teams to promote secure coding practices.

Required profile

  • 2+ years of experience in Application Security, DevSecOps, DevOps, or development with a security focus.
  • Hands‑on experience with Jenkins (declarative pipelines, shared libraries) and Podman for containerized build and scan workflows.
  • Strong knowledge of secure development frameworks and standards such as NIST SSDF, OWASP ASVS, OWASP SAMM, OWASP Top 10, SEI CERT, MITRE ATT&CK, and CWE Top 25.
  • Understanding of security testing approaches (SAST, SCA, DAST, IAST, secret scanning) and container ecosystems (Docker, Kubernetes/OpenShift).
  • Familiarity with cloud platforms (AWS, Azure, or GCP) and CIS Benchmarks.
  • Ability to read and analyze source code in Java, Node.js, JavaScript/TypeScript, Python, Go, or .NET.
  • Good communication skills in English (B1+).

Required skills

  • Jenkins
  • Podman
  • Veracode, Checkmarx, Snyk, Semgrep, GitLeaks
  • SAST, SCA, DAST, secret scanning, IAST
  • Bitbucket, SonarQube, JFrog Artifactory
  • Docker, Kubernetes/OpenShift
  • AWS, Azure, GCP
  • Java, Node.js, JavaScript/TypeScript, Python, Go.NET
  • OIDC, OAuth 2.0, SAML, JWT, mTLS, Keycloak
  • SSL/TLS, PKI, Vault
  • STRIDE, PASTA, attack trees

What we offer

  • International projects with top‑brand clients.
  • Collaboration with global, diverse, highly skilled teams.
  • Healthcare benefits and employee financial programs.
  • Paid time off and additional employee perks.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec EPAM Systems.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 4 months ago

49 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

EPAM Systems

Córdoba