Role : Cyber Security - DevSecOps
Type of role - Fixed Term Contract ( FTC - 6 Months )
Location : Sydney, Australia
:
Mandatory experience and capabilities The candidate must demonstrate:
- 8+ years of relevant experience across DevSecOps, application security, cloud security, software engineering governance, technology risk or a closely related discipline.
- 3+ years of practical experience applying AI or machine learning in software engineering, cybersecurity, DevSecOps, governance, risk or compliance use cases.
- Proven experience designing, implementing or operationalising DevSecOps governance frameworks, standards, controls or secure SDLC practices.
- Experience converting security and governance requirements into automated controls, pipeline gates, policy as code or reusable engineering patterns.
- Hands on understanding of CI/CD, source control, cloud platforms, containers, infrastructure as code, application security testing and software supply chain security.
Seeking an experienced AI and DevSecOps Subject Matter Expert to design, implement and operationalise governance, standards and controls for secure software delivery using AI enabled practices. 1. DevSecOps governance and operating model
- Assess the current DevSecOps governance maturity, delivery practices, security controls, tooling landscape and key pain points.
- Define or enhance the DevSecOps governance framework, including decision rights, accountabilities, minimum control requirements, exception management and assurance activities.
2. DevSecOps standards and control design
- Develop, review and maintain DevSecOps policies, standards, procedures, patterns and implementation guidelines.
- Define minimum security and quality controls for source code,
branch management, code review, build pipelines, artefact repositories, deployment processes and production operations.
3. AI enabled DevSecOps implementation
- Identify and prioritise use cases where AI can improve secure software delivery, governance, risk detection, remediation and engineering productivity.
- Implement or guide the implementation of AI assisted capabilities within the software development lifecycle, such as secure coding assistance, code review support, vulnerability explanation, remediation recommendations, test generation, threat modelling support, policy interpretation and control evidence generation.
4. Implementation and integration
- Translate governance requirements into implementable controls across CI/CD platforms, source control, cloud environments, security tooling and engineering workflows.
- Work with platform and engineering teams to integrate DevSecOps controls into delivery pipelines and developer workflows.
5. Stakeholder engagement and change adoption
- Facilitate workshops with engineering, security, architecture, risk, compliance, operations and delivery teams.
- Explain complex AI, security and governance concepts in explicit language suitable for both technical and non technical stakeholders.
Expected deliverables The candidate may be expected to produce or contribute to the following deliverables:
- Current state DevSecOps and AI capability assessment.
- Target state DevSecOps governance framework and operating model.
- DevSecOps policy, standards and control catalogue.
- AI enabled DevSecOps use case assessment and prioritisation.
Interested candidate can share share their resume at
[email protected] or call me on +61 283195529
📌 Cyber Security - DevSecOps (Sydney)
🏢 CareCone Group
📍 Sydney