DevSecOps SME - Contract

Professional Recruitment Australia · Sydney NSW · Contract
Posted 10d ago

DevSecOps SME - Contract

Professional Recruitment Australia
Sydney NSW

·

Contract

~$120k - $150k(Estimated)
KEY POINTS WE FOUND
  • Drive the design and implementation of application security scanning standards.
  • Lead the integration of SAST, SCA, and DAST platforms into CI/CD pipelines.
  • Collaborate with engineering teams to establish secure coding practices.

DevScope SME / Senior DevSecOps Engineer - Sydney
 
We're looking for a hands-on DevScope SME / Senior DevSecOps Engineer to drive the end-to-end design, implementation, and roll-out of application security scanning standards across enterprise engineering pipelines.
 
This is a delivery-focused engineering role, not an operational or monitoring position - ideal for a specialist who has built, integrated, and deployed SAST, SCA, and DAST platforms from the ground up.
 
You'll own the definition of security scanning boundaries (Dev Scope), establish quality gates, configure scanning engines, and automate security controls directly within active CI/CD pipelines.
 
Key Responsibilities

  • Platform Implementation & Roll-Out  - Lead the end-to-end configuration, deployment, and integration of code scanning platforms (e.g. Checkmarx, SonarQube, Veracode, Snyk, Fortify, OWASP ZAP) across enterprise repositories
  • SAST, SCA & DAST Governance  - Establish baseline rulesets, policy standards, and enforcement mechanisms for Static Application Security Testing, Software Composition Analysis, and Dynamic Application Security Testing
  • Pipeline Security Automation  - Embed automated security testing stages, quality gates, and failure conditions into modern CI/CD pipelines (e.g. GitLab CI, GitHub Actions, Azure DevOps, Jenkins)
  • Dev Scope & Triage Strategy  - Define the operational scope of security scanning, establish false-positive triage workflows, and optimise rulesets to minimise developer friction while maintaining high security coverage
  • Engineering Enablement  - Work directly with software engineering squads to provide guided remediation, establish secure coding standards, and build developer-first security practices

What You'll Bring
 
Essential:

  • Proven track record building, configuring, and deploying enterprise SAST, SCA, and DAST tooling — not just using or monitoring existing configurations
  • Strong hands-on experience integrating application security testing directly into automated CI/CD pipelines and developer tools
  • Deep understanding of the OWASP Top 10, CWE, open-source license risk, and dependency vulnerability management
  • Proficiency in scripting (Python, Bash, or PowerShell) and working with APIs to automate scanning workflows and reporting
  • Based in Sydney (or willing to work hybrid in Sydney) with full Australian working rights
Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 16 matched
Api integrationAutomation of security workflowsCi/cd pipelinesCollaborative problem solvingCweDastDependency vulnerability managementOpen-source license risk managementOwasp top 10SastScaScripting (python, bash, powershell)Secure coding standardsSecurity scanning platformsSecurity standards and policiesTeamwork and communication

Professional Recruitment Australia

DevSecOps SME - Contract | Professional Recruitment Australia | The Shout