





Remote role with mid-level experience and general AppSec expectations yields moderate competition.
Strong AppSec and cloud-native expertise required, limiting cross-industry transferability.
Requires 5+ years AppSec experience plus cloud-native and CI/CD tooling expertise, making filters strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead integration of security practices in software development lifecycle focused on cloud-native environments and automated CI/CD pipelines.
Design, maintain, and automate security tooling including SAST, DAST, SCA, secrets detection, and container scanning to ensure early security feedback to developers.
Own threat modeling, triage of vulnerabilities from various security tools and bug bounty programs, and provide secure coding standards and AI-related security guidance.
5+ years experience in application security or related software security engineering roles.
Hands-on experience with securing cloud-native environments on AWS, GCP, or Azure including containers, Kubernetes, IAM, and serverless.
Experience integrating security automation in CI/CD pipelines using tools like GitHub Actions or Jenkins covering SAST, DAST, SCA, and secrets scanning.
Proficiency in at least one programming language among Python, JavaScript/TypeScript, Java, Go, or .NET (C#).
Proven ability to lead security in product-led tech or SaaS environments, handling cloud-native architectures and developer security enablement.
Deep expertise in application security fundamentals and tooling such as Checkmarx, Burp Suite, Trivy, Checkov, and Veracode.
Experience addressing emerging AI/LLM security challenges including prompt injection and secure AI-assisted development workflows.