DevSecOps SME - Contract

Contract Type:

Location:

Sydney - NSW 

Industry:

IT

Category:

Consultant

Contact Name:

Emily

Contact Email:

emily.cawley@pra.com.au

Date Published:

22-Sep-2026

DevScope SME / Senior DevSecOps Engineer - Sydney
 
We're looking for a hands-on DevScope SME / Senior DevSecOps Engineer to drive the end-to-end design, implementation, and roll-out of application security scanning standards across enterprise engineering pipelines.
 
This is a delivery-focused engineering role, not an operational or monitoring position - ideal for a specialist who has built, integrated, and deployed SAST, SCA, and DAST platforms from the ground up.
 
You'll own the definition of security scanning boundaries (Dev Scope), establish quality gates, configure scanning engines, and automate security controls directly within active CI/CD pipelines.
 
Key Responsibilities
  • Platform Implementation & Roll-Out  - Lead the end-to-end configuration, deployment, and integration of code scanning platforms (e.g. Checkmarx, SonarQube, Veracode, Snyk, Fortify, OWASP ZAP) across enterprise repositories
  • SAST, SCA & DAST Governance  - Establish baseline rulesets, policy standards, and enforcement mechanisms for Static Application Security Testing, Software Composition Analysis, and Dynamic Application Security Testing
  • Pipeline Security Automation  - Embed automated security testing stages, quality gates, and failure conditions into modern CI/CD pipelines (e.g. GitLab CI, GitHub Actions, Azure DevOps, Jenkins)
  • Dev Scope & Triage Strategy  - Define the operational scope of security scanning, establish false-positive triage workflows, and optimise rulesets to minimise developer friction while maintaining high security coverage
  • Engineering Enablement  - Work directly with software engineering squads to provide guided remediation, establish secure coding standards, and build developer-first security practices
What You'll Bring
 
Essential:
  • Proven track record building, configuring, and deploying enterprise SAST, SCA, and DAST tooling — not just using or monitoring existing configurations
  • Strong hands-on experience integrating application security testing directly into automated CI/CD pipelines and developer tools
  • Deep understanding of the OWASP Top 10, CWE, open-source license risk, and dependency vulnerability management
  • Proficiency in scripting (Python, Bash, or PowerShell) and working with APIs to automate scanning workflows and reporting
  • Based in Sydney (or willing to work hybrid in Sydney) with full Australian working rights
APPLY NOW
APPLY NOW
Apply With Button

Share this job

Interested in this job?
Save Job
Create As Alert

Similar Jobs

SCHEMA MARKUP ( This text will only show on the editor. )