You will drive application security initiatives to reduce attack surfaces and foster secure engineering practices across the organization.
Responsibilities
• Lead security initiatives to design, build, and implement best practices across multiple engineering teams.
• Implement and enhance security automation within CI/CD pipelines.
• Maintain and improve application security solutions based on strategic priorities.
• Develop secure coding guidelines and security training for engineers.
• Investigate vulnerabilities and support incident response efforts.
• Research emerging threats and attack techniques to proactively secure applications.
Required Skills
• 8+ years of experience in application security or secure software development.
• Hands-on experience with SAST, SCA, DAST, Secrets, and API security solutions.
• Deep understanding of security for containers, web, APIs, and cloud-native workloads (AWS, Azure, GCP).
• Strong knowledge of OWASP Top 10 and modern attack vectors.
• Proficiency in at least one programming language, such as Python, Go, Java, or TypeScript.
• Experience working with CI/CD pipelines.
• Excellent communication and presentation skills for engaging with diverse stakeholders.
Preferred Skills
• Experience with Threat Modeling.
• Application Security certifications such as OSCP, GWAPT, or GCPN.