DevSecOps Security Consultant / Engineer - Contract - Sydney

Hastha SolutionsSydney, New South WalesOn-siteContractListed 1 week ago

Apply now

About this role

Urgent
requirement of DevSecOps Security Consultant / Engineer - Contract - Sydney

Requirements

Experience:

· 8+ relevant experience in Cyber Security, Cloud Security, Application Security, or DevSecOps engineering roles.

Key Responsibilities:

· Conduct comprehensive DevSecOps security discovery, assessment, and risk evaluation activities across cloud platforms, applications, and development environments.

· Perform security posture reviews using Orca Security and GitHub Advanced Security to identify vulnerabilities, misconfigurations, exposed assets, code security issues, and compliance gaps.

· Analyse cloud workloads, repositories, infrastructure configurations, and application architectures to assess security risks and recommend mitigation strategies.

· Partner with DevOps, engineering, and application teams to integrate security controls and secure-by-design principles throughout the software development lifecycle (SDLC).

· Implement and enhance security capabilities within CI/CD pipelines, including automated security testing, code scanning, secret detection, dependency analysis, and policy enforcement.

· Review and validate security findings, prioritize risks based on business impact, and provide actionable remediation guidance to stakeholders.

· Track remediation efforts and security improvements across cloud environments, containerized workloads, and source code repositories.

· Support vulnerability management activities, including identification, reporting, risk assessment, and remediation verification.

· Contribute to the development of DevSecOps standards, security baselines, governance frameworks, and operational procedures.

· Collaborate with cross-functional teams to improve cloud security architecture, compliance readiness, and security monitoring capabilities.

· Prepare assessment reports, security dashboards, executive summaries, and technical recommendations for management and project teams.

Required Skills and Experience:

· Strong hands-on experience with Orca Security and GitHub Advanced Security.

· Practical knowledge of DevSecOps methodologies, security automation, and secure software development practices.

· Experience securing CI/CD platforms and integrating security controls into development pipelines.

· Strong understanding of cloud security concepts, including identity and access management, network security, data protection, and workload security.

· Experience with vulnerability management, risk assessment, and remediation tracking.

· Knowledge of application security principles, code security testing, and software supply chain security.

· Familiarity with cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).

· Understanding of container security, Kubernetes security, and Infrastructure as Code (IaC) security practices.

· Strong analytical, troubleshooting, and problem-solving skills.

· Excellent communication and stakeholder management capabilities.

Preferred Qualifications:

· Relevant cloud security or cybersecurity certifications.

· Experience working in enterprise-scale DevSecOps and cloud transformation programs.

· Knowledge of regulatory compliance frameworks and industry security standards.

Education:

· Bachelor’s degree in computer science, Information Security, Information Technology, Engineering, or a related field.

Duration: 03 Months and
possible extension

Eligibility: Australian/NZ
Citizens/PR Holders only

Email: [email protected] (mailto:[email protected])