Check Your Resume Match Score
Scan your resume against ATS criteria for this Senior DevSecOps Engineer role at Thermo Fisher Scientific.
Apply for this position
Job Description
Work Schedule
Standard (Mon-Fri)
Environmental Conditions
Office
Job Description
Job Description
We are seeking a
Senior DevSecOps Engineer (8–12 years of experience)
with demonstrated
technical leadership experience
to lead security automation and tooling integration across
projects
. This role will focus on embedding security controls into the software delivery lifecycles specifically
SBOM generation and quality improvement, secret scanning, and SAST integration
—and automating security report generation and publishing into platforms such as
Dependency-Track
and
DefectDojo
.
You will work closely with engineering, DevOps, and security stakeholders to drive adoption of secure-by-default practices, influence technical direction, and ensure scalable, repeatable, and measurable security automation through CI/CD pipelines. You will also help raise the overall maturity of the program through mentorship, standards, and continuously improving documentation.
Key Responsibilities
Provide technical leadership for DevSecOps initiatives across MSD projects, including driving best practices, standardization, and adoption across teams.
Integrate and operationalize security tooling within MSD projects, including:
SBOM generation
and validation
Secret scanning
SAST
(Static Application Security Testing)
- Improve the
quantity (coverage)
and
quality
of generated SBOMs by defining standards, validation gates, and measurable KPIs (e.g., completeness, dependency accuracy, license metadata, component version resolution).
- Design and maintain
CI/CD automation
to generate security reports and automatically publish results to:
Dependency-Track
(SBOM ingestion / component risk analysis)
DefectDojo
(centralized vulnerability management / reporting)
- Build and maintain “security as code” patterns (pipeline templates, reusable scripts, standardized configs) to enable broad adoption across multiple repositories/teams.
- Mentor engineers and partners with development teams to improve remediation workflows by tuning rulesets, improving signal-to-noise, and ensuring findings are actionable.
- Establish secure and scalable practices for credential handling in pipelines (least privilege, secret management patterns, rotation support).
- Lead or contribute to cross-functional working groups with Security, DevOps, and Engineering to align on standards, prioritization, and measurable outcomes.
- Create, maintain, and continuously improve documentation (runbooks, guides, troubleshooting, reference architecture) to support platform adoption.
- Provide operational support for security tooling integrations, including triage of pipeline failures, report ingestion issues, and tooling upgrades.
- Contribute to continuous improvement of DevSecOps strategy, governance, and compliance alignment through automation and measurable outcomes.
Required Skills
8–12 years of experience
in DevOps / DevSecOps / Security Engineering / Platform Engineering roles with strong CI/CD ownership.
- Demonstrated
technical leadership
experience (e.g., leading initiatives, mentoring engineers, defining standards, driving cross-team adoption).
Strong hands-on experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, GitLab CI).
Practical expertise in:
SBOM generation and management
(e.g., CycloneDX or SPDX concepts, dependency discovery, artifact association)
Secret scanning
integrations and tuning
SAST
integration, configuration, and triage workflows
- Experience automating generation, transformation, and publishing of security results (APIs, JSON handling, pipelines-as-code, scripting).
- Experience integrating with or operating vulnerability/SBOM platforms such as
Dependency-Track
and
DefectDojo
(or equivalent tools).
- Strong scripting skills (Python, PowerShell, Bash, etc.) for automation and tooling glue.
- Strong troubleshooting skills across build systems, SCM workflows, containers/artifacts, and security tooling outputs.
- Ability to write clear technical documentation and drive adoption across teams.
Desirable Skills
- Experience improving SBOM
quality metrics
and implementing policy gates (completeness checks, schema validation, build provenance, license metadata enrichment).
- Familiarity with SCA/vulnerability workflows and risk triage at scale (severity normalization, deduplication, SLA reporting).
- Experience with container security and artifact scanning (images, binaries, registries), plus SBOM provenance linkage.
- Knowledge of secure software supply chain practices (SLSA concepts, signing/attestation, provenance, dependency pinning).
- Experience working in regulated or security-focused environments with strong auditability requirements.
- Exposure to internal developer platform patterns (golden pipelines, reusable actions, templates, centralized governance).
Key Requirements & Skills
- 8–12 years of experience in DevOps, DevSecOps, Security Engineering, or Platform Engineering
- Demonstrated technical leadership experience
- Hands-on experience integrating security tools into CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI)
- Expertise in SBOM generation and management
- Expertise in secret scanning integrations and tuning
- Expertise in SAST integration, configuration, and triage workflows
- Experience with Dependency-Track and DefectDojo
- Strong scripting skills (Python, PowerShell, Bash)
Frequently Asked Questions
How to apply for Senior DevSecOps Engineer at Thermo Fisher Scientific?
Click the "Apply via CareerScan" button on this page.
What is the salary for this role?
Salary details will be discussed during the interview.
What experience is required?
8+ years of experience is required.
Is this position still open?
Yes, currently active and accepting applications.
Senior DevSecOps Engineer
Thermo Fisher Scientific · Bangalore
