yoinka

Senior DevSecOps Engineer

Thermo Fisher Scientific

Bangalore, Karnātaka, IndiaFull TimeSeniorH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Bangalore, Karnātaka, India
Employment
Full Time
Work model
On-Site
Level
Senior
H-1B history
76 approvals (FY2023)
Posted
Aug 25, 2026

Skills

CI/CDCybersecurityGitGitHub ActionsJenkinsPythonShell

About this role

Work Schedule Standard (Mon-Fri) Environmental Conditions Office Job Description Job Description We are seeking a  Senior DevSecOps Engineer (8–12 years of experience)  with demonstrated  technical leadership experience  to lead security automation and tooling integration across  projects . This role will focus on embedding security controls into the software delivery lifecycles specifically  SBOM generation and quality improvement, secret scanning, and SAST integration —and automating security report generation and publishing into platforms such as  Dependency-Track  and  DefectDojo . You will work closely with engineering, DevOps, and security stakeholders to drive adoption of secure-by-default practices, influence technical direction, and ensure scalable, repeatable, and measurable security automation through CI/CD pipelines. You will also help raise the overall maturity of the program through mentorship, standards, and continuously improving documentation.

Key Responsibilities

Provide technical leadership for DevSecOps initiatives across MSD projects, including driving best practices, standardization, and adoption across teams. Integrate and operationalize security tooling within MSD projects, including: SBOM generation  and validation Secret scanning SAST  (Static Application Security Testing) Improve the  quantity (coverage)  and  quality  of generated SBOMs by defining standards, validation gates, and measurable KPIs (e.g., completeness, dependency accuracy, license metadata, component version resolution). Design and maintain  CI/CD automation  to generate security reports and automatically publish results to: Dependency-Track  (SBOM ingestion / component risk analysis) DefectDojo  (centralized vulnerability management / reporting) Build and maintain “security as code” patterns (pipeline templates, reusable scripts, standardized configs) to enable broad adoption across multiple repositories/teams. Mentor engineers and partners with development teams to improve remediation workflows by tuning rulesets, improving signal-to-noise, and ensuring findings are actionable. Establish secure and scalable practices for credential handling in pipelines (least privilege, secret management patterns, rotation support). Lead or contribute to cross-functional working groups with Security, DevOps, and Engineering to align on standards, prioritization, and measurable outcomes. Create, maintain, and continuously improve documentation (runbooks, onboarding guides, troubleshooting, reference architecture) to support platform adoption. Provide operational support for security tooling integrations, including triage of pipeline failures, report ingestion issues, and tooling upgrades. Contribute to continuous improvement of DevSecOps strategy, governance, and compliance alignment through automation and measurable outcomes.

Required Skills

8–12 years of experience  in DevOps / DevSecOps / Security Engineering / Platform Engineering roles with strong CI/CD ownership. Demonstrated  technical leadership  experience (e.g., leading initiatives, mentoring engineers, defining standards, driving cross-team adoption). Strong hands-on experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, GitLab CI). Practical expertise in: SBOM generation and management  (e.g., CycloneDX or SPDX concepts, dependency discovery, artifact association) Secret scanning  integrations and tuning SAST  integration, configuration, and triage workflows Experience automating generation, transformation, and publishing of security results (APIs, JSON handling, pipelines-as-code, scripting). Experience integrating with or operating vulnerability/SBOM platforms such as  Dependency-Track  and  DefectDojo  (or equivalent tools). Strong scripting skills (Python, PowerShell, Bash, etc.) for automation and tooling glue. Strong troubleshooting skills across build systems, SCM workflows, containers/artifacts, and

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Senior DevSecOps Engineer at Thermo Fisher Scientific, Bangalore, Karnātaka, India | Yoinka