
Security Engineer – SAST & SCA
Sonata Software6 days ago
Bengaluru, IndiaMid Level / Senior
Responsibilities
- Perform static code analysis and open-source dependency scanning using SAST and SCA tools.
- Analyze and prioritize security findings and work with development teams on remediation.
- Integrate security scanning into CI/CD pipelines and automate security workflows.
- Manage vulnerability lifecycles, reporting, and compliance metrics.
- Promote secure coding practices and provide remediation guidance.
- Support DevSecOps initiatives and shift-left security adoption.
Requirements
- 3–6+ years of experience in Application Security, DevSecOps, or secure software development.
- Hands-on experience with SAST tools such as Checkmarx, Fortify, Veracode, or CodeQL.
- Experience with SCA tools such as Snyk, Black Duck, Mend (WhiteSource), Sonatype, or Dependabot.
- Strong understanding of OWASP Top 10, secure coding practices, and vulnerability management.
- Experience integrating security tools with GitHub, GitLab, Jenkins, or Azure DevOps.
- Scripting knowledge in Python, Bash, or PowerShell.
- Excellent communication and collaboration skills.
- Preferred experience with SBOM, container security, IaC security, or cloud-native application security.
- CSSLP, GWAPT, or OSCP certifications are a plus.
Benefits
- The role is located in Noida.
- Sonata Software offers an opportunity to work on AI-led modernization and challenging enterprise solutions with a diverse team of innovators.
- Sonata Software is an Equal Opportunity Employer.