DevSecOps SME - Contract

PRA ·www.pra.com.au

Location Sydney, NSW, Australia
Type Full time
Level Mid
Source Shazamme
IT
Apply direct
DevScope SME / Senior DevSecOps Engineer - Sydney
 
We're looking for a hands-on DevScope SME / Senior DevSecOps Engineer to drive the end-to-end design, implementation, and roll-out of application security scanning standards across enterprise engineering pipelines.
 
This is a delivery-focused engineering role, not an operational or monitoring position - ideal for a specialist who has built, integrated, and deployed SAST, SCA, and DAST platforms from the ground up.
 
You'll own the definition of security scanning boundaries (Dev Scope), establish quality gates, configure scanning engines, and automate security controls directly within active CI/CD pipelines.
 
Key Responsibilities
  • Platform Implementation & Roll-Out - Lead the end-to-end configuration, deployment, and integration of code scanning platforms (e.g. Checkmarx, SonarQube, Veracode, Snyk, Fortify, OWASP ZAP) across enterprise repositories
  • SAST, SCA & DAST Governance - Establish baseline rulesets, policy standards, and enforcement mechanisms for Static Application Security Testing, Software Composition Analysis, and Dynamic Application Security Testing
  • Pipeline Security Automation - Embed automated security testing stages, quality gates, and failure conditions into modern CI/CD pipelines (e.g. GitLab CI, GitHub Actions, Azure DevOps, Jenkins)
  • Dev Scope & Triage Strategy - Define the operational scope of security scanning, establish false-positive triage workflows, and optimise rulesets to minimise developer friction while maintaining high security coverage
  • Engineering Enablement - Work directly with software engineering squads to provide guided remediation, establish secure coding standards, and build developer-first security practices
What You'll Bring
 
Essential:
  • Proven track record building, configuring, and deploying enterprise SAST, SCA, and DAST tooling — not just using or monitoring existing configurations
  • Strong hands-on experience integrating application security testing directly into automated CI/CD pipelines and developer tools
  • Deep understanding of the OWASP Top 10, CWE, open-source license risk, and dependency vulnerability management
  • Proficiency in scripting (Python, Bash, or PowerShell) and working with APIs to automate scanning workflows and reporting
  • Based in Sydney (or willing to work hybrid in Sydney) with full Australian working rights

Frequently asked questions

Who is hiring for the DevSecOps SME - Contract role?
PRA is hiring for the DevSecOps SME - Contract position, a Shazamme client. Apply directly on the employer's career site.
Where is the DevSecOps SME - Contract job located?
The DevSecOps SME - Contract role with PRA is based in Sydney, NSW, AU.
Is the DevSecOps SME - Contract role full-time or contract?
This is a full time position at PRA.
What experience level is the DevSecOps SME - Contract role?
The DevSecOps SME - Contract position is aimed at mid-level candidates.
How do I apply for the DevSecOps SME - Contract role at PRA?
Apply directly on PRA's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct