At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.
We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.
We are seeking a hands-on DevScope SME / Senior DevSecOps Engineer to drive the end-to-end design, implementation, and roll-out of application security scanning standards across enterprise engineering pipelines.
This is not an operational or monitoring position—it is a delivery-focused engineering role for a specialist who has built, integrated, and deployed SAST, SCA, and DAST platforms from the ground up. You will take ownership of defining security scanning boundaries (Dev Scope), establishing quality gates, configuring scanning engines, and automating security controls directly within active CI/CD pipelines.
Key Responsibilities
Platform Implementation & Roll-Out: Lead the end-to-end configuration, deployment, and integration of code scanning platforms (e.g., Checkmarx, SonarQube, Veracode, Snyk, Fortify, or OWASP ZAP) across enterprise repositories.
SAST, SCA & DAST Governance: Establish baseline rulesets, policy standards, and enforcement mechanisms for Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST).
Pipeline Security Automation: Embed automated security testing stages, quality gates, and failure conditions seamlessly into modern CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Azure DevOps, Jenkins).
Dev Scope & Triage Strategy: Define the operational scope of security scanning, establish false-positive triage workflows, and optimize rulesets to minimize developer friction while maintaining high security coverage.
Engineering Enablement: Work directly with software engineering squads to provide guided remediation, establish secure coding standards, and build developer-first security
Essential Experience:
Proven Implementation Track Record: Demonstrated experience building, configuring, and deploying enterprise SAST, SCA, and DAST tooling (not just using or monitoring existing configurations).
DevSecOps Automation: Strong hands-on experience integrating application security testing directly into automated CI/CD pipelines and developer tools.
AppSec & Vulnerability Management: Deep understanding of the OWASP Top 10, CWE, open-source license risk, and dependency vulnerability management.
Scripting & Integration: Proficiency in scripting (Python, Bash, or PowerShell) and working with APIs to automate scanning workflows and reporting.
Location: Based in Sydney (or willing to work hybrid in Sydney) with full Australian working rights.
Why NCS?
This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.
Ready to make extraordinary happen?
We'd love to hear from you.
We celebrate diversity and inclusion
We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.
Important information
Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.
Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.