What are the responsibilities and job description for the Application Security Tester / DevSecOps position at Mphasis?
Job Title: Application Security Tester / DevSecOps
Berkeley Heights, NJ
Contract
Experience: 10 Years
________________________________________
Key Responsibilities
Enforce Security Gates Across All Stacks
• Convert Fortify SAST from advisory/report-only mode to a blocking gate: Critical and High severity findings must fail the build for the Modern (.NET Core/AKS), Legacy (.NET/IIS), and Core COBOL (mainframe) pipelines.
• Define and tune Fortify rulesets, filters, and issue-suppression policies per stack to minimize false positives while preserving enforcement integrity.
• Drive the exception/waiver process for findings that cannot be remediated immediately (compensating controls, documented risk acceptance, expiry dates).
Extend and Mature Security Tooling Coverage
• Extend Sonatype SCA to the legacy IIS/.NET Framework 4.8 / VB.NET stack, including NuGet and legacy package dependency scanning.
• Assess Fortify (or Arcad) rulesets for COBOL, pilot on the mainframe codebase, and deploy where technically feasible; document coverage gaps and compensating controls where static analysis is not viable.
• Maintain and tune WebInspect DAST scans against staging/pre-prod environments for all applications.
• Integrate Dynatrace and Splunk signals into the security workflow for runtime visibility and post-deployment monitoring.
DevSecOps Pipeline Engineering
• Embed SAST (Fortify), DAST (WebInspect), and SCA (Sonatype) directly into CI/CD pipelines across GitHub Actions, Ansible, and Harness.
• Implement build-breaker logic and quality/security gates so pipelines fail deterministically on policy violations, with clear developer-facing feedback.
• Integrate SonarQube for code quality and security hotspots alongside Fortify, avoiding tool overlap/conflict.
• Manage secure artifact promotion through Nexus, including scanning gates prior to promotion between environments.
• Automate vulnerability remediation workflows: auto-ticketing, developer notification, re-scan verification, and closure evidence for audit purposes.
Establish Remediation SLAs
• Stand up a remediation pipeline with a target SLA of under 30 days for Critical/High findings across SAST, DAST, and SCA.
• Build tracking, reporting, and escalation workflows (dashboards, ticket auto-creation, aging reports) so overdue findings are visible to engineering leadership and the CISO.
• Define severity-based SLA tiers (e.g., Critical: 15 days, High: 30 days, Medium: 90 days) and get sign-off from engineering and compliance stakeholders.
Governance, Metrics & Stakeholder Management
• Report pipeline enforcement status, SLA compliance, and risk trends to the CISO and engineering leadership on a regular cadence.
• Partner with development leads across all three stacks to drive remediation without stalling delivery velocity.
• Contribute security control evidence to ISO 27001, SOC 2, NIST CSF, and ISO 42001 audit cycles.
• Maintain documentation for tool configuration, gate logic, exception handling, and rollback procedures.
AI-Augmented Findings Orchestration & Remediation
• Operate AI agents to orchestrate findings intake across Fortify, WebInspect, and Sonatype - correlating, deduplicating, and prioritizing results into a single actionable queue.
• Use AI-assisted triage to distinguish true positives from false positives, reducing manual review load while maintaining audit-defensible reasoning for every disposition.
• Use AI agents for auto-generate remediation guidance and, where appropriate, remediation code suggestions for developers, with human review gates before merge.
• Establish guardrails, human-in-the-loop checkpoints, and audit trails for all AI-driven security decisions to satisfy ISO 27001 / SOC 2 / ISO 42001 evidentiary requirements.
• Measure and report AI-assisted triage performance (false-positive reduction rate, mean time to triage, agent accuracy drift).
Tools & Platforms
• 10 years in Application Security / DevSecOps, with at least 2-3 years in a lead capacity.
• Proven, hands-on experience implementing and enforcing SAST/DAST/SCA gates in CI/CD pipelines.
• Direct experience with Fortify (SAST) in an enforcing/blocking configuration, ideally across multiple technology stacks.
• Working knowledge of Sonatype (or equivalent SCA) and WebInspect (or equivalent DAST) in production pipelines.
• Practical exposure to at least two of the three target stacks: cloud-native .NET/Kubernetes, legacy .NET/IIS, and mainframe/COBOL; candidates with all three are strongly preferred.
• Experience with GitHub Actions, Ansible, and/or Harness pipeline authoring, including custom actions/plugins for security gating.
• Familiarity with Nexus repository management and secure artifact promotion practices.
• Experience defining and operating remediation SLA programs with measurable compliance reporting.
• Exposure to compliance frameworks relevant to a lean, cloud-native SMB environment: ISO 27001, SOC 2, NIST CSF, GDPR; ISO 42001 awareness a plus.
• Strong stakeholder management skills - able to hold the line on security gates while working constructively with developers across very different tech generations.
• Hands-on experience with AI agents / LLM-based tooling for security findings orchestration, triage, and remediation workflows.
• Demonstrated experience reducing false-positive rates through AI-assisted or ML-assisted triage, including training/fine-tuning models or rule-based classifiers on historical findings data.
• Understanding of AI governance and safety practices (human-in-the-loop review, audit logging, model drift monitoring) as applied to security decision-making.
Salary : $55 - $65