Posted on: 28/05/2026
Must-have skills / project experience :
- 4+ years of hands-on experience in application security/DevSecOps, with strong experience in SAST, SCA, and DAST (and ability to operate these in CI/CD).
- Experience with leading AppSec tools such as Checkmarx, Veracode, Fortify, Burp Suite, OWASP ZAP, Snyk, Mend/WhiteSource, Black Duck, or similar.
- Strong understanding of SSDLC, OWASP Top 10, secure coding practices, and common web/API vulnerabilities (authentication/authorization, injection, SSRF, deserialization, misconfiguration).
- Experience integrating security controls into Jenkins, GitLab CI, GitHub Actions, Azure DevOps, or similar CI/CD platforms, including pipeline templates, quality gates, and exception processes.
- Python proficiency for AppSec automation (e.g., pipeline integrations, parsing/enrichment, and custom checks); experience with scripting to operationalize security at scale.
- Hands-on experience designing/building AI agents or agentic workflows for security/engineering use cases, including tool/function calling and multi-step orchestration (frameworks such as LangChain/LangGraph/CrewAI/AutoGen or equivalent).
- Experience in vulnerability triage, remediation validation, developer enablement, and reporting.
- Working knowledge of threat modeling, security architecture review, and secure design principles.
- Hands-on experience performing API security testing and guiding remediation for authorization and abuse-case issues (e.g., BOLA/BFLA) in modern application architectures.
- Familiarity with cloud-native application security, containers/Kubernetes, IaC, and secrets management concepts in delivery pipelines.
- Awareness of security risks in LLM-enabled applications (prompt injection, sensitive data exposure, insecure tool/function calling) and ability to apply basic mitigating controls during delivery.
- Strong verbal and written communication skills, including the ability to explain risk and remediation to both technical and business stakeholders.
Preferred / good-to-have skills :
- Experience conducting security architecture reviews and identifying design-level weaknesses.
- Experience using OWASP ASVS or equivalent control frameworks to define and validate AppSec requirements.
- Experience with container/Kubernetes security, IaC scanning, secrets detection, and policy-as-code (e.g., OPA/Gatekeeper or similar concepts/tools).
- Exposure to software supply-chain security practices such as SBOM, artifact signing/verification, dependency pinning, and build provenance (concepts aligned to SLSA).
- Knowledge of regulatory/compliance requirements impacting application security programs.
- Familiarity with AISecOps frameworks and guidance (e.g., OWASP Top 10 for LLM Applications, OWASP Agentic Security, MITRE ATLAS, NIST AI RMF, Google SAIF).
- Experience with LLM guardrails and safety controls (e.g., NeMo Guardrails, Llama Guard, or similar) and/or agent sandboxing patterns.
- Exposure to AI/ML supply-chain security (e.g., model registries, signed model artifacts, ML-BOM concepts) and governance for model and data lineage.
- Exposure to IAST, runtime application protection, or unified AppSec platforms.
AI / GenAI capabilities (delivery-focused) :
- Use AI-assisted techniques responsibly for triage, summarization, and remediation suggestions with strong validation and secure handling of client data.
- Create and execute GenAI/LLM security test cases (prompt injection/jailbreaks, data exfiltration paths, tool/function-calling abuse) and recommend guardrails and monitoring.
- Understand RAG risks (data poisoning, retrieval manipulation) and apply hardening controls (content filtering, grounding checks, least privilege for connectors).
- Experience using AI-assisted AppSec tooling for vulnerability triage, false-positive reduction, exploitability context, and remediation recommendation-while validating outputs before use.
- Ability to create GenAI/LLM application test cases (prompt injection, data exfiltration paths, jailbreak attempts, and abuse scenarios) and translate them into actionable engineering controls/guardrails.
- Familiarity with securing RAG patterns and tool/function calling integrations (least privilege for connectors, allow-listing tools, validation of model outputs, and protection against unsafe actions).
- Familiarity with reviewing and governing AI-generated code (secure coding patterns, secrets leakage checks, licensing considerations for generated snippets where applicable) within standard PR workflows.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1639836