Senior Cybersecurity DevSecOps Analyst
Caterpillar Inc.About the role
Career Area:
Technology, Digital and DataJob Description:
Your Work Shapes the World at Caterpillar Inc.
When you join Caterpillar, you're joining a global team who cares not just about the work we do – but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here – we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.
Senior Cybersecurity DevSecOps Analyst
Role Definition:
Join Caterpillar as a senior cybersecurity analyst on the Caterpillar Cybersecurity Vulnerability Management Team. This role will be a SAST/SCA Program Leader focused on SAST, SCA, Secrets scanning, DevSecOps transition, web application security testing, and security tool integrations within SDLC.
What You Will Do:
SAST/SCA Program Leader
Advocate “Shift Left” and DevSecOps transformation.
Provide operational support for static application security testing (SAST), software composition analysis (SCA), secrets scanning.
Deliver technical support in the integration of security tools in CI/CD pipelines and S-SDLC
Educate and provide support to web application teams, owners, developers on application security, SAST/DAST tools and vulnerability management.
Work with VM team leadership and peers to drive efficiency into vulnerability management processes in ServiceNow and application security services.
Maintain knowledge on existing security procedures and directives related to application security and vulnerability management.
What You Have:
Bachelor’s degree in Cybersecurity, Security Engineering/Architecture, Computer Science, or related experience.
Cybersecurity, Penetration Testing, and/or Vulnerability Management hands on experience.
Experience with SAST/SCA/Secret Scanning tools - GitHub Advanced Security, CodeQL, Dependabot, Checkmarx, etc.
Good knowledge of OWASP Guidelines and industry vulnerability scoring standards for application security.
Good Knowledge of software development processes, integration of security assessments in Software development life cycle (SDLC) process, secure coding is required.
Top Candidate Will Also Have:
One or more professional information security certification from an accredited institution (CISSP, CCSP, CSSLP, CISM, GISCP, GWAPT, GWEB etc.)
Experience developing and testing apps in .NET or Java and other leading modern programming languages and technologies.
Experience with newer development frameworks
Experience with cloud security: Amazon AWS, Windows Azure
Excellent critical thinking, problem-solving, as well as written/verbal communication skills
Skills Descriptors:
Communicating Complex Concepts:
Knowledge of effective presentation tools and techniques to ensure clear understanding; ability to use summarization and simplification techniques to explain complex technical concepts in simple, plain language appropriate to the audience.
Consulting:
Knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply consulting knowledge appropriately.
Cybersecurity Standards and Policies:
Knowledge of developing cybersecurity policies, standards, and procedures; ability to develop and communicate policies, standards and procedures that guide interactions with customers.
A goal-driven mindset, focused on achieving objectives and continuously improving security measures.
Cybersecurity Risk Management:
Knowledge of tools, techniques, approaches, and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.
Information Security Management:
Knowledge of the processes, tools, and techniques of information security management; ability to deploy and monitor information security systems, while detecting, controlling, and preventing violations of IT security.
Information Security Technologies:
Knowledge of technologies and technology-based solutions dealing with information security
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s