Lead Security Test Engineer DevSecOps

Hybrid in Englewood Cliffs, NJ, US • Posted 1 day ago • Updated 5 hours ago
Contract W2
Contract Independent
Contract Corp To Corp
12 Months
No Travel Required
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • API
  • Application Security
  • Security Testing
  • DevSecOps
  • Automation
  • Cloud Computing
  • Security Architecture
  • Cloud Security

Summary

Job Title : Lead Security Test Engineer – DevSecOps
Location: Englewood Cliffs, NJ (Hybrid ) 
Job Type : Contract 

Experience: 10+ Years
Interview Requirement: Final round will be conducted in person. NJ local candidates are preferred.

Job Summary

We are looking for a Lead Security Test Engineer with strong DevSecOps and Application Security experience to design, implement, and execute security testing throughout the software development lifecycle.

The ideal candidate will have hands-on experience with SAST, DAST, SCA, API Security, Penetration Testing, Vulnerability Assessment, and Threat Modeling, along with the ability to integrate security testing into CI/CD pipelines.

Key Responsibilities

  • Design and execute security testing strategies for web applications, APIs, microservices, mobile applications, and cloud environments.
  • Perform SAST, DAST, SCA, API security, container security, and infrastructure security testing.
  • Conduct vulnerability assessments and penetration testing and validate remediation.
  • Integrate security testing tools and automated security gates into CI/CD pipelines.
  • Develop security testing automation using Python, Java, JavaScript, or Bash.
  • Collaborate with Development, QA, DevOps, Cloud, and Security teams to identify and remediate vulnerabilities early.
  • Implement shift-left security and DevSecOps controls across the SDLC.
  • Configure and manage security tools for SAST, DAST, SCA, secrets scanning, container scanning, and IaC security.
  • Perform security testing of Docker/Kubernetes environments.
  • Test REST and GraphQL APIs, including authentication and authorization mechanisms.
  • Integrate security checks with Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, or similar tools.
  • Analyze vulnerability findings, prioritize risks, and track remediation through closure.
  • Develop security test cases, automation frameworks, reports, and security metrics.
  • Participate in threat modeling and security architecture reviews.
  • Support security and compliance standards including OWASP Top 10, OWASP ASVS, SANS, NIST, and CIS Controls.
  • Stay current with emerging security threats, testing methodologies, and DevSecOps tools.

Mandatory Skills

  • Application Security Testing
  • SAST
  • DAST
  • SCA
  • API Security Testing
  • Penetration Testing
  • Vulnerability Assessment
  • Threat Modeling
  • OWASP
  • DevSecOps
  • Security Test Automation
  • CI/CD Security Integration

Desirable Skills

  • AWS Secrets Manager
  • AWS / Cloud Security
  • Docker / Kubernetes Security
  • REST / GraphQL API Security
  • Jenkins / GitHub Actions / GitLab CI/CD / Azure DevOps
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: prutx001
  • Position Id: 9072987
  • Posted 1 day ago
Contact the job poster
PK

Pavan Kalva

Recruiter @ Prudent Technologies and Consulting
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Englewood Cliffs, New Jersey

Today

Contract

USD55.0/HOURLY - USD60.0/HOURLY

New York, New York

Today

Easy Apply

Full-time

USD240,000 - USD260,000

Hybrid in New York, New York

18d ago

Easy Apply

Full-time

170,000 - 200,000

New York, New York

11d ago

Full-time

Search all similar jobs