App Sac Specialist
Listed on 2026-09-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world.
For additional information, visit us at
Job Description:
Job DescriptionTitle:
SAST Checkmarx Specialist
Location:
Princeton NJ
Duration:
Full Time
Job Title:
Application Security - Onsite
Role Summary
Lead the execution and optimization of enterprise Application Security testing services, including SAST, SCA, Secrets Detection, and DAST. Drive secure SDLC adoption through CI/CD integration, vulnerability validation, infrastructure vulnerability management, risk-based remediation tracking, SBOM management, and security metrics reporting.
Checkmarx tool experience is Mandatory
- Perform continuous and incremental application security testing using SAST, SCA, Secrets Detection, and DAST tools.
- Proficient in Checkmarx – architect level (Mandatory)
- Validate findings, eliminate false positives, and support vulnerability remediation activities.
- Integrate security scanning into CI/CD pipelines and enforce secure development gates.
- Manage SBOM generation, open-source dependency risks, CVE tracking, and vulnerability exposure reporting.
- Track remediation SLAs, TTD/TTR metrics, and application security KPIs.
- Partner with development, Dev Sec Ops , and platform engineering teams to drive remediation and continuous security improvements.
- Support security assessments, tool optimization, reporting, and developer enablement initiatives.
- Review the report before publishing and lead the report readout meetings with the stakeholders
- Provide guidance and Technical governance to the team members
- 10+ years of experience in Application Security, Secure SDLC, or Dev Sec Ops .
- Hands-on experience operating enterprise App Sec scanning platforms and vulnerability management processes.
- Experience integrating security testing into CI/CD pipelines and cloud-native environments.
- Strong understanding of OWASP Top 10, secure coding practices, and software supply chain security.
- SAST:
Checkmarx. - SCA & SBOM:
Checkmarx - DAST & API Security:
Checkmarx - Secrets Detection:
Git Guardian/ Git Hub Secret Scanning. - Dev Sec Ops :
Azure Dev Ops/ Git Hub Actions/ Jenkins/ Git Lab CI/CD. - Container & Cloud Security:
Prisma Cloud/ Wiz/ Aqua/ Microsoft Defender for Cloud. - Reporting & ITSM:
Service Now/ Power BI/ Grafana
- CEH/Security+/Certified Dev Sec Ops Professional/AWS/Azure Security Specialty
Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards.
Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption
Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.
Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks.
Maintain audit…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).