HamburgerMenu
hirist

Application Security Lead - SAST/DevSecOps

PeopleLogic Business Solutions
7 - 10 Years
Multiple Locations

Posted on: 09/09/2026

Job Description

Role Summary :

Lead the execution and optimization of enterprise Application Security testing services, including SAST, SCA, Secrets Detection, and DAST.

Drive secure SDLC adoption through CI/CD integration, vulnerability validation, risk-based remediation tracking, SBOM management, and security metrics reporting.

Key Responsibilities :

- Perform continuous and incremental application security testing using SAST, SCA, Secrets Detection, and DAST tools.

- Validate findings, eliminate false positives, and support vulnerability remediation activities.

- Integrate security scanning into CI/CD pipelines and enforce secure development gates.

- Manage SBOM generation, open-source dependency risks, CVE tracking, and vulnerability exposure reporting.

- Track remediation SLAs, TTD/TTR metrics, and application security KPIs.

- Partner with development, DevSecOps, and platform engineering teams to drive remediation and continuous security improvements.

- Support security assessments, tool optimization, reporting, and developer enablement initiatives.

- Review the report before publishing and lead the report readout meetings with the stakeholders.

- Provide guidance and Technical governance to the team members.

Technical Skills & Tool Experience :

- SAST : Checkmarx, Veracode, Fortify, SonarQube, GitHub Advanced Security.

- SCA & SBOM : Fortify, Checkmarx, Snyk, Black Duck.

- DAST & API Security : Fortify, Checkmarx, Burp Suite, Invicti, Acunetix.

- Secrets Detection : GitGuardian, GitHub Secret Scanning.

- DevSecOps : Azure DevOps, GitHub Actions, Jenkins, GitLab CI/CD.

- Container & Cloud Security : Prisma Cloud, Wiz, Aqua, Microsoft Defender for Cloud.

- Reporting & ITSM : ServiceNow, Power BI, Grafana.

Experience :

- 7 - 10 years of experience in Application Security, Secure SDLC, or DevSecOps.

- Experience in Team management.

- Hands-on experience operating enterprise AppSec scanning platforms and vulnerability management processes.

- Experience integrating security testing into CI/CD pipelines and cloud-native environments.

- Strong understanding of OWASP Top 10, secure coding practices, and software supply chain security.

Preferred Certifications :

- CEH, Security+, Certified DevSecOps Professional, AWS/Azure Security Specialty.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...