Urgent requirement of DevSecOps Security Consultant / Engineer - Contract - Sydney
Requirements
Experience:
· 8+ relevant experience in Cyber Security, Cloud Security, Application Security, or DevSecOps engineering roles.
Key Responsibilities:
· Conduct comprehensive DevSecOps security discovery, assessment, and risk evaluation activities across cloud platforms, applications, and development environments.
· Perform security posture reviews using Orca Security and GitHub Advanced Security to identify vulnerabilities, misconfigurations, exposed assets, code security issues, and compliance gaps.
· Analyse cloud workloads, repositories, infrastructure configurations, and application architectures to assess security risks and recommend mitigation strategies.
· Partner with DevOps, engineering, and application teams to integrate security controls and secure-by-design principles throughout the software development lifecycle (SDLC).
· Implement and enhance security capabilities within CI/CD pipelines, including automated security testing, code scanning, secret detection, dependency analysis, and policy enforcement.
· Review and validate security findings, prioritize risks based on business impact, and provide actionable remediation guidance to stakeholders.
· Track remediation efforts and security improvements across cloud environments, containerized workloads, and source code repositories.
· Support vulnerability management activities, including identification, reporting, risk assessment, and remediation verification.
· Contribute to the development of DevSecOps standards, security baselines, governance frameworks, and operational procedures.
· Collaborate with cross-functional teams to improve cloud security architecture, compliance readiness,
and security monitoring capabilities.
· Prepare assessment reports, security dashboards, executive summaries, and technical recommendations for management and project teams.
Required Skills and Experience:
· Solid hands-on experience with Orca Security and GitHub Advanced Security.
· Practical knowledge of DevSecOps methodologies, security automation, and secure software development practices.
· Experience securing CI/CD platforms and integrating security controls into development pipelines.
· Strong understanding of cloud security concepts, including identity and access management, network security, data protection, and workload security.
· Experience with vulnerability management, risk assessment, and remediation tracking.
· Knowledge of application security principles, code security testing, and software supply chain security.
· Familiarity with cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).
· Understanding of container security, Kubernetes security, and Infrastructure as Code (IaC) security practices.
· Strong analytical, troubleshooting, and problem-solving skills.
· Excellent communication and stakeholder management capabilities.
Preferred Qualifications:
· Relevant cloud security or cybersecurity certifications.
· Experience working in enterprise-scale DevSecOps and cloud transformation programs.
· Knowledge of regulatory compliance frameworks and industry security standards.
Education:
· Bachelor’s degree in computer science, Information Security, Information Technology, Engineering, or a related field.
Duration: 03 Months and possible extension
Eligibility: Australian/NZ Citizens/PR Holders only
Email:
[email protected]
📌 DevSecOps Security Consultant / Engineer - Contract - Sydney
🏢 Hastha Solutions
📍 Sydney