> Markdown version of [/jobs/ext/2973818-security-consultant-penetration-testing-devsecops](https://www.wearedevelopers.com/jobs/ext/2973818-security-consultant-penetration-testing-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Consultant - Penetration Testing & DevSecOps - **Company:** Capgemini - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $70,176.0 - $170,040.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cyber Security, Continuous Integration, DevOps, Github, Mobile Application Software, Kali Linux, Nmap, Open Web Application Security, Systems Development Life Cycle, Red Team (Cyber Security), Zero Trust Network Access, Secure Coding, Web Application Security, Software Engineering, SonarQube, Software Vulnerability Management, Web Applications, Policy as Code, Cloud Platform System, Spring Cloud, Large Language Models, Software Security, Mitre Att&ck, Veracode, Cloudformation, GWAPT, Kubernetes, Information Technology, Metasploit, Nessus, Checkmarx, Terraform, Devsecops, Qualys, Docker, Jenkins, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 18, 2026 - **Apply:** https://www.careerjet.com/job/usace751dd052d113b1099aa08ff2ae6eb/eaa ## About the Role * Bachelor's degree in Computer Science, Information Security, Engineering, or a related field., * 5-8 years of hands-on cybersecurity experience. * Minimum 3+ years of experience conducting application and API penetration testing. * Experience implementing or supporting DevSecOps initiatives within CI/CD environments. Technical Skills * Strong understanding of: * Web Application Security * API Security * Secure SDLC * OWASP Top 10 * OWASP API Top 10 * MITRE ATT&CK * Threat Modeling * Vulnerability Management * Hands-on experience with: * Burp Suite Professional * Nmap * Nessus / Qualys / Tenable * Metasploit * Kali Linux * Checkmarx * Veracode * Snyk * SonarQube * GitHub Actions / Azure DevOps / Jenkins, * OSCP (Preferred) * CRTO * PNPT * CEH * GWAPT * GPEN * CISSP * CCSP * Azure Security Engineer Associate * AWS Security Specialty Additional Skills : * Experience with container security (Docker, Kubernetes). * Experience conducting cloud penetration testing. * Understanding of Infrastructure as Code (Terraform, CloudFormation). * Familiarity with Red Team methodologies and adversary simulation. * Experience with AI/LLM security testing is a plus. * Exposure to Zero Trust Architecture and Secure-by-Design principles. * Excellent communication, consulting, and stakeholder management skills. ## Description We are seeking a Senior Security Consultant - Penetration Testing & DevSecOps with 5-8 years of cybersecurity experience and strong expertise in application penetration testing, offensive security, DevSecOps, SSDLC, and vulnerability management. The role focuses on conducting security assessments across applications, APIs, cloud environments, and CI/CD pipelines, while collaborating with development and engineering teams to embed security throughout the software development lifecycle. The ideal candidate combines strong technical skills, a proactive security mindset, and the ability to communicate risks effectively to both technical and business stakeholders. Your Role Penetration Testing & Offensive Security * Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure. * Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities following industry-standard methodologies such as OWASP, PTES, NIST, and MITRE ATT&CK. * Identify security vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations. * Execute security assessments against modern architectures including microservices, containers, Kubernetes, and cloud-native applications. * Develop proof-of-concepts to demonstrate security weaknesses and attack paths. * Prepare detailed technical reports and executive summaries for customers and stakeholders. DevSecOps & Secure SDLC * Integrate security controls and testing into CI/CD pipelines. * Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions. * Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices. * Participate in security architecture reviews, threat modeling exercises, and secure design assessments. * Automate security testing and compliance validation within DevOps toolchains. * Develop security guardrails and policy-as-code capabilities to improve software security posture. Vulnerability Management & Security Engineering * Perform vulnerability triage, risk prioritization, and remediation tracking. * Support continuous security monitoring and risk assessment activities. * Analyze emerging threats, attack techniques, and security trends to improve testing methodologies. * Assist in development of security standards, procedures, and best practices. * Work with engineering, cloud, and infrastructure teams to enhance organizational security posture. Stakeholder Engagement * Present findings and recommendations to developers, architects, engineering teams, and leadership. * Provide security consulting throughout the software development lifecycle. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)