DevSecOps Application Security Engineer
Infosys - Richardson, TX
Hiring: DevSecOps Application Security Engineer Company: Infosys Location: Richardson, TX Job Posted Time: 2026-09-09 18:07:47 Employment Type: On-site Target Skills & Keywords : CI/CD, Clean Architecture, Compliance, DAST, GANs, Microservices, OWASP, SAST, SCA, SonarQube, TestNG About the job Required Skills: •Application Security Testing: Conduct SAST/SCA using GHAS and DAST using Burp Suite; validate and classify vulnerabilities aligned with OWASP. •DevSecOps & Integration: Integrate GHAS into CI/CD, automate scans across SDLC, configure policies, reduce false positives, and enable shift-left security with development teams. •Vulnerability Management: Analyze findings, provide remediation guidance, track vulnerabilities through lifecycle, and support risk-based prioritization. •Reporting & Stakeholder Management: Prepare technical and executive reports, communicate findings with stakeholders, and support audits, compliance, and AppSec initiatives. Qualifications: •Security Advisory & Review: Conduct secure code reviews and architecture level assessments; Coordinate with development teams on secure coding and mitigation strategies. •Knowledge Of: SDLC and DevSecOps practices, microservices/API/cloud security, strong analytical/problem-solving skills, and stakeholder communication/consulting experience. •Good to Have: •Exposure to SAST (Fortify, SonarQube), DAST (Netsparker, Fortify on Demand), and SCA (BlackDuck, Dependabot) tools. •Certifications: CEH, OSCP, GWAPT, CSSLP, CISSP. •Experience in threat modeling and architecture reviews. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!