PFE: DevSecOps Automation for API Security: Continuous Integration, Vulnerability Testing, and Compliance Validation
Il y a 22 heures
Tunis, Tunis, Tunisie
Security Accent
Temps plein
This project aims to develop a CI/CD pipeline that automates API security validation, vulnerability testing, and compliance checks using open -source DevSecOps tools integrated with WSO2 Identity Server. <\/span><\/span><\/span><\/span>
<\/span><\/span><\/p>
Problem Statement
<\/span><\/span><\/h4>
Manual security
validation in API deployments increases risk, delays releases, and may fail to
meet compliance requirements such as OWASP Top 10 or GDPR. Automation is
required to ensure continuous, consistent security enforcement<\/span><\/span><\/span><\/span>
<\/span><\/span><\/p>
Methodology for Solution
<\/span><\/span><\/h4>
• Build CI/CD pipeline with Jenkins or GitHub Actions.
<\/div>
<\/div>
• Integrate SAST/DAST tools like OWASP ZAP, SonarQube, and Trivy.
<\/div>
<\/div>
• Automate vulnerability reporting and policy enforcement before deployment.
<\/div>
<\/div>
• Connect WSO2 Identity Server for pre -deployment API validation and access control.
<\/div>
<\/div>Expected Deliverables
<\/div>
<\/div>
Expected Deliverables
<\/span><\/span><\/h4>
• Automated DevSecOps pipeline with integrated testing and validation.
<\/div>
<\/div>
• Security compliance reports aligned with OWASP and GDPR.
<\/div>
<\/div>
• Pre -deployment security validation workflows.
<\/div>
<\/div>
<\/div><\/span>
Must Have
<\/div>
<\/div>
<\/div><\/span>
Requirements<\/h3>
Must Have
<\/h4>
• Strong experience with CI/CD tools such as Jenkins or GitHub Actions.
<\/div>
<\/div>
• Knowledge of DevSecOps principles and integration of security within development pipelines.
<\/div>
<\/div>
• Proficiency with WSO2 Identity Server for identity validation and access control in API security contexts.
<\/div>
<\/div>
• Experience with vulnerability testing tools such as OWASP ZAP, SonarQube, and Trivy.
<\/div>
<\/div>
• Familiarity with Docker for containerized environments and secure builds.
<\/div>
<\/div>
• Skills in Bash scripting and YAML for automation and configuration.
<\/div>Nice to Have<\/b>
<\/div>
Nice to Have<\/b>
<\/h4>
• Understanding of Kubernetes for container orchestration and deployment.
<\/div>
<\/div>
• Knowledge of OWASP Top 10 and GDPR compliance standards for API security validation.
<\/div>
<\/div>
• Experience with security reporting and dashboard automation.
<\/div>
<\/div>
• Familiarity with infrastructure as code (IaC) tools such as Terraform or Ansible.
<\/div>
<\/div>
• Awareness of policy -as -code frameworks like Open Policy Agent (OPA).
<\/div>
<\/div><\/span>
Academic Benefits<\/span>
<\/div>
<\/div><\/span>
Benefits<\/h3>
Academic Benefits<\/span>
<\/h4>
Gain hands -on experience by applying your academic knowledge to real -world projects under expert guidance.<\/span>
<\/div>
<\/div>
<\/span>
<\/div>Organizational & Professional Benefits<\/span>
<\/div>
Organizational & Professional Benefits<\/span>
<\/h4>
Immerse yourself in a structured professional environment with mentorship and real opportunities for growth.<\/span>
<\/div>
<\/div>Technical & Learning Benefits<\/span>
<\/div>
<\/div>
Technical & Learning Benefits<\/span>
<\/h4>
Develop cutting -edge skills in IAM, cybersecurity, and software development through agile, collaborative work.<\/span>
<\/div>
<\/div>Human & Cultural Benefits<\/span>
<\/div>
<\/div>
Human & Cultural Benefits<\/span>
<\/h4>
Join a people -first culture that values teamwork, inclusion, and personal growth.<\/span>
<\/div>
<\/div>Career Development Benefits<\/span>
<\/div>
<\/div>
Career Development Benefits<\/span>
<\/h4>
Build a strong foundation for your future career through meaningful projects, mentorship, and lasting opportunities.<\/span>
<\/div><\/span>
<\/div><\/span>
Recevez des alertes pour des offres similaires
Recevez des offres d'emploi pour PFE: DevSecOps Automation for API Security: Continuous Integration, Vulnerability Testing, and Compliance Validation