Senior DevSecOps / Application Security Engineer

Avia Solutions Group — Lithuania · Posted ~3 hours ago

Senior Full-time

Skills

Application security DevSecOps Secure SDLC Security engineering SSDLC Cloud security

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security engineering opportunity focused on improving secure development practices, integrating security throughout the software lifecycle, and partnering with engineering and operations teams.

Highlights

Senior cybersecurity role focused on embedding security into software development processes and collaborating across engineering teams.

Description

Avia Solutions Group is the leading aviation business group, operating across all the continents with offices in Ireland, USA, Asia Pacific, UAE, Lithuania, South Africa, Australia. Backed by 12,000 highly skilled aviation professionals, the group is the largest global ACMI (Aircraft, Crew, Maintenance, and Insurance) provider, operating around 140 aircraft fleet. The Group also provides various aviation services such as MRO (maintenance, repair, and overhaul), pilots and crew training, ground handling and other interconnected solutions We are looking for a highly motivated Senior DevSecOps / Application Security Engineer to join our Cyber Security team. In this role, you will drive the implementation and continuous improvement of our Secure Software Development Lifecycle (SSDLC) practices. You will work closely with software development, architecture, DevOps, and security teams to ensure security is embedded throughout the software development process, from design and development to deployment and operations. You will be responsible for implementing and managing application security testing platforms, integrating security controls into CI/CD pipelines, performing threat modeling activities, and helping establish a strong Secure-by-Design culture across the Avia Solutions Group. Key Responsibilities Design, implement, and maintain the Secure Software Development Lifecycle (SSDLC). Integrate security controls and automated security testing into CI/CD pipelines. Deploy, configure, and manage application security tooling, including: Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Software Composition Analysis (SCA) Secret Detection scanning Container Security scanning Infrastructure as Code (IaC) Security Scanning Application Security Posture Management (ASPM) Cloud Security Posture Management (CSPM) Ensure effective integration of security tooling with development platforms such as GitHub, GitLab, Azure DevOps. Facilitate and conduct Threat Modeling sessions for applications, systems, and new technology initiatives. Collaborate with development teams to identify, prioritize, and remediate security vulnerabilities. Perform application security reviews and provide secure design recommendations. Maintain application security standards, secure coding guidelines, and supporting processes. Analyze security findings, assess risks, and support remediation efforts. Measure and report on AppSec and SSDLC KPIs and security maturity metrics. Promote security awareness and secure development practices across development and engineering teams. Continuously evaluate and improve application security capabilities. Required Qualifications 4+ years of experience in: Application Security or DevSecOps.Hands-on experience implementing and managing application security solutions. Strong understanding of OWASP Top 10, OWASP OWASP SAMM, Secure Coding principles, Secure-by-Design concepts. Application Security Posture Management (ASPM). Cloud Security Posture Management (CSPM). Experience conducting Threat Modeling using methodologies such as STRIDE, or equivalent. Practical experience with CI/CD environments and DevOps practices. Good understanding of software development methodologies and modern application architectures, design patterns, clean code practises. Understanding of AI security, IT infrastructure, Cloud environments, white-box pentesting. Preferred Qualifications .Experience securing cloud-native environments (Azure, AWS, or GCP). Experience with Kubernetes, containers, and container security. Knowledge of API security and microservices architectures. Experience implementing enterprise SSDLC programs. Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS Controls, NIS2, ASVS, MVSP. Any globally known professional certifications. What do we offer? Opportunity to work in a vibrant international and ever-growing business aviation environment.An opportunity to shape and mature the DevSecOps and Application Security program. Professional development and certification opportunities. Opportunities for professional and personal growth; foreign language training.Gym and Yoga classes for your physical health.Children’s room where you can leave your kids to play with supervision.Well-being initiatives focused on creating a healthy, balanced and engaging work environment.Various benefits related to employee life cycle in organization.Parking or public transport tickets.Electrical cars spots near the office.Discounts and special offers from various partners. Salary starting from 6000 EUR (including taxes), with potential range based on experience. Join the multicultural environment of one of the largest aviation groups in the world and take a pivotal role in driving Cyber Security success of an industry leader! Final candidates will be required to undergo an internal company’s background verification process.