Department Manager - DevSecOps Security
On-siteBangkok, Bangkok, Thailand
Job Summary
Manage day-to-day operations and continuous improvement of CP Axtra's security testing platforms, including Checkmarx, SonarQube, Qualys WAS, OWASP ZAP, Spectral, and IaC scanning tools for Terraform and containers. Tune scan policies, onboard new repositories, troubleshoot pipeline integrations, and train developers to interpret results while reducing false positive rates. Extend coverage into container and infrastructure-as-code security as the cloud-native footprint grows. Work closely with the Application Security Lead on strategy to ensure developers trust the tools and fix actionable findings.
Required Qualifications
- 5+ years of experience managing DevSecOps or application security testing platforms in a production environment
- Hands-on expertise with at least 2 of: Checkmarx, SonarQube, Snyk, Veracode, Fortify, or equivalent SAST/SCA platforms
- Experience integrating security scanning into CI/CD pipelines — GitHub Actions, Azure DevOps, Jenkins, or GitLab CI
- Strong understanding of DAST tools and web application scanning (Qualys WAS, OWASP ZAP, Burp Suite Enterprise, or equivalent)
- Ability to tune scan policies, write custom rules, and reduce false positive rates
- Clear communication skills for working with developers who may not have security backgrounds
Desired Qualifications
- Experience with Spectral or other secrets detection platforms
- Background in software development — understanding build systems, dependency management, and package registries
- Familiarity with SonarQube quality profiles and custom rule development
- Experience managing scanning platforms at scale (100+ repositories, multiple development teams)
- Knowledge of supply chain security: SBOM generation, dependency confusion prevention, provenance verification
- CDE (Certified DevSecOps Engineer), CSSLP, or equivalent certification
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.