Hiring.Camp

Senior DevSecOps Engineer

Thermofisher

·

Today

Location
India - Bangalore - 5th floor, building no. 3, Prestige technostar
Workplace
Hybrid
Type
Full-time
Department
Engineering
Seniority
Senior
Experience
8+ years
Source
Workday

Description

Work Schedule

Standard (Mon-Fri)

Environmental Conditions

Office

Job Description

Job Description

We are seeking a Senior DevSecOps Engineer (8–12 years of experience) with demonstrated technical leadership experience to lead security automation and tooling integration across projects. This role will focus on embedding security controls into the software delivery lifecycles specifically SBOM generation and quality improvement, secret scanning, and SAST integration—and automating security report generation and publishing into platforms such as Dependency-Track and DefectDojo.

You will work closely with engineering, DevOps, and security stakeholders to drive adoption of secure-by-default practices, influence technical direction, and ensure scalable, repeatable, and measurable security automation through CI/CD pipelines. You will also help raise the overall maturity of the program through mentorship, standards, and continuously improving documentation.

Key Responsibilities

  • Provide technical leadership for DevSecOps initiatives across MSD projects, including driving best practices, standardization, and adoption across teams.
  • Integrate and operationalize security tooling within MSD projects, including:
    • SBOM generation and validation
    • Secret scanning
    • SAST (Static Application Security Testing)
  • Improve the quantity (coverage) and quality of generated SBOMs by defining standards, validation gates, and measurable KPIs (e.g., completeness, dependency accuracy, license metadata, component version resolution).
  • Design and maintain CI/CD automation to generate security reports and automatically publish results to:
    • Dependency-Track (SBOM ingestion / component risk analysis)
    • DefectDojo (centralized vulnerability management / reporting)
  • Build and maintain “security as code” patterns (pipeline templates, reusable scripts, standardized configs) to enable broad adoption across multiple repositories/teams.
  • Mentor engineers and partners with development teams to improve remediation workflows by tuning rulesets, improving signal-to-noise, and ensuring findings are actionable.
  • Establish secure and scalable practices for credential handling in pipelines (least privilege, secret management patterns, rotation support).
  • Lead or contribute to cross-functional working groups with Security, DevOps, and Engineering to align on standards, prioritization, and measurable outcomes.
  • Create, maintain, and continuously improve documentation (runbooks, onboarding guides, troubleshooting, reference architecture) to support platform adoption.
  • Provide operational support for security tooling integrations, including triage of pipeline failures, report ingestion issues, and tooling upgrades.
  • Contribute to continuous improvement of DevSecOps strategy, governance, and compliance alignment through automation and measurable outcomes.

Required Skills

  • 8–12 years of experience in DevOps / DevSecOps / Security Engineering / Platform Engineering roles with strong CI/CD ownership.
  • Demonstrated technical leadership experience (e.g., leading initiatives, mentoring engineers, defining standards, driving cross-team adoption).
  • Strong hands-on experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, GitLab CI).
  • Practical expertise in:
    • SBOM generation and management (e.g., CycloneDX or SPDX concepts, dependency discovery, artifact association)
    • Secret scanning integrations and tuning
    • SAST integration, configuration, and triage workflows
  • Experience automating generation, transformation, and publishing of security results (APIs, JSON handling, pipelines-as-code, scripting).
  • Experience integrating with or operating vulnerability/SBOM platforms such as Dependency-Track and DefectDojo (or equivalent tools).
  • Strong scripting skills (Python, PowerShell, Bash, etc.) for automation and tooling glue.
  • Strong troubleshooting skills across build systems, SCM workflows, containers/artifacts, and security tooling outputs.
  • Ability to write clear technical documentation and drive adoption across teams.

Desirable Skills

  • Experience improving SBOM quality metrics and implementing policy gates (completeness checks, schema validation, build provenance, license metadata enrichment).
  • Familiarity with SCA/vulnerability workflows and risk triage at scale (severity normalization, deduplication, SLA reporting).
  • Experience with container security and artifact scanning (images, binaries, registries), plus SBOM provenance linkage.
  • Knowledge of secure software supply chain practices (SLSA concepts, signing/attestation, provenance, dependency pinning).
  • Experience working in regulated or security-focused environments with strong auditability requirements.
  • Exposure to internal developer platform patterns (golden pipelines, reusable actions, templates, centralized governance).

Skills

PythonJenkinsCI/CDGitHubGitLabDevOpsCompliance

Similar Jobs

30

DevSecOps Engineer - Senior

Koniag Government Services · Washington, DC, USA

Yesterday

Senior DevSecOps Engineer

Movilges

5 days ago

Sr. DevSecOps Engineer

M9 Solutions · Reston, VA - TS/SCI clearance with CI Polygraph required · Onsite

6 days ago

Senior DevSecOps Engineer

Dark Wolf Solutions · Chantilly/Herndon, VA +1

6 days ago

Senior DevSecOps Engineer

Gsknch · Bengaluru Campus 31, India

1 week ago

Senior DevSecOps Engineer

Lynx Software Technologies · Denver, CO

1 week ago

Senior DevSecOps Engineer

Vivid · Almaty +3 · Remote

1 week ago

Senior DevSecOps Engineer

Vivid · Almaty +3 · Remote

1 week ago

Senior DevSecOps Engineer

Vivid · Almaty +3 · Remote

1 week ago

Senior DevSecOps Engineer

ALTEN Technology USA · Denver, Colorado, United States +1 · Onsite

1 week ago

Sr. DevSecOps Engineer

M9 Solutions · Reston, VA - TS/SCI clearance required · Hybrid, Onsite

1 week ago

Senior DevSecOps Engineer

Helpware · MX

1 week ago

Senior DevSecOps Engineer

Steampunk Inc. · McLean, VA, US

2 weeks ago

Senior DevSecOps Engineer

Leidos · 2682 Huntsville AL, United States of America

2 weeks ago

Senior DevSecOps Engineer

Leidos · 6714 Eagan MN, United States of America +2

2 weeks ago

DevSecOps Engineer, Senior

Booz Allen Hamilton · USA, NC, Fort Bragg (2175 Reilly Rd), United States of America

2 weeks ago

Sr. DevSecOps Engineer

Rancher Government Solutions · Reston, VA

2 weeks ago

Senior DevSecOps Engineer

Peraton · San Diego, CA, US · Remote, Hybrid, Onsite

3 weeks ago

Senior DevSecOps Engineer

Bluestaq US External · Colorado Springs +1

3 weeks ago

Senior DevSecOps Engineer

Leidos · 3398 Defence Plaza Melbourne VIC Australia - Customer Site

3 weeks ago

Senior DevSecOps Engineer

Prime Solutions Group, Inc. · Goodyear, AZ

3 weeks ago

Senior DevSecOps Engineer

Encora · Brazil · Remote, Hybrid

3 weeks ago

Senior DevSecOps Engineer

Virtuous · Phoenix, AZ +1 · Remote

4 weeks ago

Senior DevSecOps Engineer

Fintel Connect · Vancouver, British Columbia, Canada

1 month ago

Senior DevSecOps Engineer

Myhcm · London - St Pancras Campus, United Kingdom · Hybrid

1 month ago

Senior DevSecOps Engineer

Parsons Corporation · USA CO Boulder (6304 Spine Road), United States of America · Onsite

1 month ago

Senior DevSecOps Engineer

PactFi · New York, NY · Hybrid

1 month ago

DevSecOps Engineer, Senior

Booz Allen Hamilton · USA, VA, Alexandria (6361 Walker Ln), United States of America

1 month ago

DevSecOps Engineer, Senior

Booz Allen Hamilton · USA, VA, Alexandria (6361 Walker Ln), United States of America

1 month ago

DevSecOps Engineer, Senior

Booz Allen Hamilton · USA, VA, Alexandria (6361 Walker Ln), United States of America

1 month ago
Senior DevSecOps Engineer at Thermofisher | Hiring.Camp