Job summary
Embeds the clients security and compliance requirements into Flowsource pipelines and the control plane configuring SAST Checkmarx SCA Prisma Cloud container image scanning IaC scanning and Veracode to enforce policy as code aligned to the clients compliance framework SOC 2 PCI DSS HIPAA ISO 27001 Owns the security quality gates vulnerability disclosure workflows and the leadership facing compliance dashboards inside Flowsource Configures tooling against client owned policy does not set po
Responsibilities
Configure SAST Checkmarx SCA Prisma Cloud image scanning IaC scanning and Veracode integrations inside Flowsource pipeline templates
Codify the clients security policy as enforceable gates severity thresholds allow deny lists exception workflows
Operate the vulnerability triage and disclosure workflow surfaced inside Flowsource route findings to the right squad with SLA
Build and maintain leadership facing compliance dashboards open critical mean time to remediate control coverage
Partner with DevOps and Pipeline Integrator to keep pipeline gates consistent across every onboarded application
Support client audit readiness by exporting Flowsource evidence packs scan history gate enforcement remediation timelines
Stay aligned with the client compliance framework SOC 2 PCI ISO HIPAA and surface any gaps to the FDE Lead
Required Skills and Experience
6 plus years application security or DevSecOps engineering experience
Hands on with at least two of Checkmarx Prisma Cloud Veracode Snyk SonarQube security profiles
Working knowledge of at least one compliance framework SOC 2 PCI DSS HIPAA ISO 27001
Container image scanning and IaC scanning experience Trivy Checkov tfsec kube bench helpful
Comfortable building executive facing reporting able to talk policy with security leadership and tooling with developers
Flowsource Tooling and Tech Stack
SAST Checkmarx
SCA Prisma Cloud
Application security testing Veracode
Container image scanning and IaC scanning toolchains
Flowsource pipeline security gates and compliance dashboards
Success Metrics
Percentage of pipelines with mandatory security gates enforced
Mean time to remediate critical high findings
Open critical severity findings trend must trend down
Audit evidence completeness for in scope applications
Number of policy exceptions must remain bounded and time limited
ข่าวประชาสัมพันธ์แบบสำเร็จรูปของ Cognizant
Cognizant(NASDAQ: CTSH) คือผู้สร้าง AI และผู้ให้บริการด้านเทคโนโลยี ซึ่งเชื่อมช่องว่างระหว่างการลงทุนใน AI และมูลค่าขององค์กรด้วยการสร้างโซลูชัน AI แบบครบวงจรให้แก่ไคลเอนต์ของเรา ความเชี่ยวชาญเชิงลึกด้านอุตสาหกรรม กระบวนการ และวิศวกรรมของเรา ช่วยให้เราผสานบริบทเฉพาะขององค์กรเข้ากับระบบเทคโนโลยีเพื่อเพิ่มศักยภาพมนุษย์ สร้างผลลัพธ์ที่จับต้องได้ และช่วยให้องค์กรระดับโลกก้าวนำหน้าอยู่เสมอในโลกที่เปลี่ยนแปลงไป ดูวิธีดำเนินการได้ที่ cognizant.ai หรือ @cognizant
ข้อมูลการจ้างงานเพิ่มเติม
ข้อมูลเกี่ยวกับค่าตอบแทนมีความถูกต้อง ณ วันที่ประกาศรับสมัครงานนี้ Cognizant ขอสงวนสิทธิ์ในการแก้ไขข้อมูลดังกล่าวได้ตลอดเวลา ภายใต้กฎหมายที่เกี่ยวข้อง
ผู้สมัครอาจถูกขอให้เข้ารับการสัมภาษณ์แบบพบตัวต่อตัวหรือผ่านการประชุมทางวิดีโอ นอกจากนี้ ผู้สมัครอาจถูกขอให้นำเอกสารประจำตัวที่ออกโดยหน่วยงานของรัฐ หรือบัตรประจำตัวที่ออกโดยรัฐบาลซึ่งยังมีผลบังคับใช้ มาแสดงในระหว่างการสัมภาษณ์แต่ละครั้ง
Cognizant เป็นนายจ้างที่ให้โอกาสอย่างเท่าเทียม การสมัครและการพิจารณาคุณสมบัติของคุณจะไม่ถูกตัดสินจากเชื้อชาติ สีผิว เพศ ศาสนา ความเชื่อ รสนิยมทางเพศ อัตลักษณ์ทางเพศ สัญชาติ ความพิการ ข้อมูลทางพันธุกรรม การตั้งครรภ์ สถานะทหารผ่านศึก หรือคุณลักษณะอื่นใดที่ได้รับการคุ้มครองตามกฎหมายของรัฐบาลกลาง รัฐ หรือท้องถิ่น







