Job Description Overview The Global Application Security & DevSecOps Lead is responsible for, operating and continuously improving the organisation’s application security function across the complete software development lifecycle. The role owns the policies, technical standards, engineering controls, security testing services, Azure DevOps integrations, application security platforms and governance processes required to ensure that internally developed and externally supplied applications are designed, built, tested and released securely. This is both a leadership and hands-on engineering role. The role holder must be capable of defining the global AppSec strategy while also configuring, integrating, operating, troubleshooting and improving the underlying security tools. The role will embed automated and risk-based security controls into Azure DevOps repositories and CI/CD pipelines at enterprise scale, covering potentially hundreds of Azure DevOps projects and thousands of repositories. The role is accountable for ensuring that security controls are: Technically effective. Integrated into engineering workflows. Proportionate to application risk. Reliable enough to support mandatory release gates. Properly tuned to minimise false positives. Measurable and auditable. Supported by clear operating procedures. Adopted consistently across global development teams. Your role Principal accountabilities AppSec strategy and operating model The role holder will: Maintain the global Application Security and DevSecOps strategy. Establish the AppSec function’s mandate, service catalogue, governance model and engagement process. Define the division of responsibilities between AppSec, engineering, cloud security, architecture, SOC, vulnerability management, risk and compliance. Develop a risk-based AppSec control framework for different application types and criticality levels. Establish minimum security requirements for internally developed, externally developed and SaaS applications. Define application risk tiers based on factors such as: Data classification. Internet exposure. Transaction value. Regulatory impact. Privileged access. Customer impact. Business criticality. Safety impact. Use of AI or autonomous functionality. Maintain an AppSec roadmap covering people, process, technology and maturity. Undertake periodic maturity assessments against NIST SSDF and OWASP SAMM. Develop annual investment, licensing and resource plans. Own the AppSec tooling budget and supplier roadmap. Produce executive-level risk reporting for the CISO and technology leadership. Represent Application Security at architecture, engineering and risk governance forums. AppSec service catalogue Establish and operate defined services covering: Secure code review. SAST onboarding. SCA onboarding. DAST onboarding. API security testing. Mobile security testing. Pipeline security assessment. Secure Azure DevOps configuration. Secrets scanning. IaC and container scanning. Penetration-test scoping and coordination. AppSec exception assessment. Secure release assurance. Developer security training. Security Champions support. Supplier application security review. Application incident root-cause analysis. Secure software development lifecycle Secure SDLC governance The role holder will: Define mandatory security activities for each SDLC stage. Establish security acceptance criteria for epics, features and user stories. Define mandatory evidence required for production release. Develop risk-based security release gates. Ensure emergency-release procedures include proportionate security checks and retrospective review. Define criteria for when applications require manual review or penetration testing. Integrate AppSec activities with enterprise architecture and change-management processes. About you Scope of the function The role owns or governs the following application security capabilities: Secure software development lifecycle governance. Secure coding standards. Static application security testing. Software composition analysis. Dynamic application security testing. Interactive application security testing, Manual secure code review. Application penetration testing. API security testing. Cloud-native and serverless application security. Container and application image security during build. Infrastructure-as-code security within application delivery pipelines. Secrets detection and prevention. Software supply-chain security. SBOM generation and governance. Build provenance, artifact integrity and signing. Azure DevOps repository and pipeline security. Application security tool ownership and operation. Security Champions and developer enablement. Application security exception and risk-acceptance processes. Application security metrics, reporting and assurance. Third-party and externally developed software assurance. Security of AI-enabled applications and AI-generated code. Product security incident support and root-cause analysis. Explicit scope boundary: not enterprise vulnerability management This role does not own the central enterprise vulnerability management function. The following remain outside the role unless separately assigned: Operating-system vulnerability scanning. General infrastructure vulnerability scanning. Network-device vulnerability management. Endpoint vulnerability management. Firmware vulnerability management. Enterprise patch management. Cloud-host vulnerability remediation. Runtime host and virtual-machine vulnerability management. General CSPM remediation ownership. SOC monitoring and incident queue management. Enterprise-wide CVE reporting unrelated to applications. Infrastructure penetration testing. The AppSec function nevertheless owns the management of security defects, including: Validation and triage of AppSec findings. Removal of false positives and duplicate findings. Assignment of findings to the correct engineering teams. Definition of application-security remediation requirements. Verification that fixes are effective. Management of AppSec-specific exceptions. Reporting on application-security exposure. Escalation of overdue high-risk application findings. For containers, the function owns build-time image and Dockerfile security. Runtime host, node and deployed-container vulnerability management should remain with Cloud Security, Platform Security or Vulnerability Management, subject to a defined RACI. Rewards & benefits Explore the rewards and benefits that help you thrive – at every stage of your life and your career. This includes: Comprehensive life insurance coverage. Premium medical insurance for you and your dependents. Generous annual leave balance. Flexible and hybrid work solutions. Remote work opportunities outside of country. Company gratuity scheme. Discretionary bonus program. Relocation assistance. Employee Wellbeing Program: 24/7 access to specialists in finance, legal matters, family care, personal health, fitness, and nutrition. Seize every opportunity to sharpen your skills, expand your expertise, and be recognized for the impact you make. About AtkinsRéalis We're AtkinsRéalis , a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world's infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. We're committed to leading our clients across our various end markets to engineer a better future for our planet and its people. Find out more. Worker Type Employee Job Type Regular At AtkinsRéalis , we seek to hire individuals with diverse characteristics, backgrounds and perspectives. We strongly believe that world-class talent makes no distinctions based on gender, ethnic or national origin, sexual identity and orientation, age, religion or disability, but enriches itself through these differences.
Team Member - Engineering (Electrical)
Dr Reddy's Laboratories Limited
Team Member - Engineering (Civil)
Dr Reddy's Laboratories Limited
Sr. Technology Associate/Specialist
Colgate
Amazon Connect SRE
Miratech
AWS Site Reliability Engineer
Miratech
Assistant Manager - Projects & Engineering, Castrol
Bpinternational