Senior Security Analyst – Application Security, DevSecOps

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Software Mind

Software Mind

1001 - 5000 employees

Founded 1999

🤖 Artificial Intelligence

☁️ SaaS

📡 Telecommunications

💰 Private Equity Round on 2020-12

Artificial Intelligence • SaaS • Telecommunications

Software Mind is a technology company that specializes in software development and digital transformation services. With a focus on AI and cloud solutions, the company offers a wide range of services including custom software development, mobile app development, and cloud consulting. Software Mind serves various industries such as financial services, telecom, biotech, and media, providing tailored solutions to accelerate digital transformations and business growth globally.

📋 Description

• Partner with development teams to embed secure coding practices throughout the SDLC, shifting security from a final gate to a shared, integrated responsibility • Assess current development practices against Secure SDLC standards, identify gaps, and drive a phased maturity roadmap with measurable milestones • Lead developer enablement initiatives — secure coding guidance, threat modeling, and a security champions program — that build durable capability within engineering teams • Integrate and tune SAST, DAST, SCA, and secrets scanning in CI/CD pipelines (Azure DevOps, Bitbucket) to deliver fast, in-workflow feedback with minimal friction • Evaluate prospective products, platforms, SaaS tools, and developer tooling to confirm alignment with security best practices before adoption • Conduct architecture and design reviews, assessing authentication, authorization, data handling, encryption, logging, and multi-tenancy considerations • Review third-party and supply chain risk — dependencies, integrations, AI/ML components, and vendor security posture — and define conditions for safe use • Produce clear, risk-based assessments and recommendations (approve, approve-with-conditions, or reject) for engineering and security leadership • Partner with vendor risk and compliance functions to align product reviews with SOC 2 and broader control requirements • Implement policy-as-code guardrails and infrastructure-as-code security controls across Azure/M365 cloud environments • Drive cloud posture improvements — configuration hardening, CIS benchmark alignment, WAF, and network segmentation • Establish supply chain security controls including dependency governance and code signing

🎯 Requirements

• 5+ years of experience in Application Security, DevSecOps, or a similar role • Demonstrated experience maturing an engineering organization through Secure SDLC adoption — not just deploying tools • Hands-on AppSec and DevSecOps background: SAST/DAST/SCA, CI/CD pipeline security, secrets management • Strong product and technology security review experience — ability to assess a new platform or tool and articulate concrete risks and mitigations • Experience with CI/CD and source control tooling (Azure DevOps, Bitbucket, or equivalents) • Familiarity with secure development frameworks (NIST SSDF, OWASP SAMM/ASVS, BSIMM) • Cloud security experience in AWS and/or Azure • Strong collaboration and communication skills — able to coach developers and present risk to both technical and executive audiences • +90% English proficiency (written and spoken, minimum B2 level)

🏖️ Benefits

• Flexible schedules • An authentic work-life balance • Payment in US Dollars

Apply Now

Similar Jobs

🕒 June 5

TransUnion

10,000+ employees

💸 Finance

🔐 Security

👥 B2C

DevOps Engineer in Costa Rica focusing on cloud environments and collaboration with global teams. Designing and managing infrastructure for reliable cloud-based systems at TransUnion.

🇨🇷 Costa Rica – Remote

💰 Post-IPO Debt on 2018-04

⏰ Full Time

🟡 Mid-level

🟠 Senior

⛑ DevOps & Site Reliability Engineer (SRE)

Ansible

Cloud

DNS

Docker

Firewalls

Google Cloud Platform

Grafana

Jenkins

Kubernetes

Linux

Microservices

Prometheus

Python

Terraform

Unix

🕒 May 30

GFT Technologies

10,000+ employees

🔒 Cybersecurity

📋 Compliance

☁️ SaaS

AWS Network Engineer designing and implementing AWS-native networking solutions for Cloud Networking initiatives. Focus on replacing legacy controls with scalable patterns and integrating into platform pipelines.

AWS

Cloud

DNS

Terraform

🕒 May 30

GFT Technologies

10,000+ employees

🔒 Cybersecurity

📋 Compliance

☁️ SaaS

DevOps & Network Engineer designing AWS-native networking capabilities for Cloud Networking initiative. Senior-level role requiring expertise in AWS networking and Terraform.

🗣️🇪🇸 Spanish Required

AWS

DNS

Terraform

🕒 May 22

Experian

10,000+ employees

🤖 Artificial Intelligence

🤝 B2B

☁️ SaaS

Senior DevOps Engineer at Experian designing cloud-native infrastructure and CI/CD platforms. Collaborating with teams to ensure scalable, secure, and reliable environments.

AWS

Cloud

Distributed Systems

Kubernetes

Linux

Python

Terraform

🕒 April 29

GFT Technologies

10,000+ employees

🔒 Cybersecurity

📋 Compliance

☁️ SaaS

🗣️🇪🇸 Spanish Required

Ansible

Jenkins

Linux

Postgres

Python

SQL

Terraform