Posted on: 09/09/2026
Role Summary :
Lead the execution and optimization of enterprise Application Security testing services, including SAST, SCA, Secrets Detection, and DAST.
Drive secure SDLC adoption through CI/CD integration, vulnerability validation, risk-based remediation tracking, SBOM management, and security metrics reporting.
Key Responsibilities :
- Perform continuous and incremental application security testing using SAST, SCA, Secrets Detection, and DAST tools.
- Validate findings, eliminate false positives, and support vulnerability remediation activities.
- Integrate security scanning into CI/CD pipelines and enforce secure development gates.
- Manage SBOM generation, open-source dependency risks, CVE tracking, and vulnerability exposure reporting.
- Track remediation SLAs, TTD/TTR metrics, and application security KPIs.
- Partner with development, DevSecOps, and platform engineering teams to drive remediation and continuous security improvements.
- Support security assessments, tool optimization, reporting, and developer enablement initiatives.
- Review the report before publishing and lead the report readout meetings with the stakeholders.
- Provide guidance and Technical governance to the team members.
Technical Skills & Tool Experience :
- SAST : Checkmarx, Veracode, Fortify, SonarQube, GitHub Advanced Security.
- SCA & SBOM : Fortify, Checkmarx, Snyk, Black Duck.
- DAST & API Security : Fortify, Checkmarx, Burp Suite, Invicti, Acunetix.
- Secrets Detection : GitGuardian, GitHub Secret Scanning.
- DevSecOps : Azure DevOps, GitHub Actions, Jenkins, GitLab CI/CD.
- Container & Cloud Security : Prisma Cloud, Wiz, Aqua, Microsoft Defender for Cloud.
- Reporting & ITSM : ServiceNow, Power BI, Grafana.
Experience :
- 7 - 10 years of experience in Application Security, Secure SDLC, or DevSecOps.
- Experience in Team management.
- Hands-on experience operating enterprise AppSec scanning platforms and vulnerability management processes.
- Experience integrating security testing into CI/CD pipelines and cloud-native environments.
- Strong understanding of OWASP Top 10, secure coding practices, and software supply chain security.
Preferred Certifications :
- CEH, Security+, Certified DevSecOps Professional, AWS/Azure Security Specialty.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1669930