





Specialized AppSec tooling and mid-level scope reduce applicant density versus generalist developer roles.
Requires deep AppSec and DevSecOps expertise, limiting cross-industry interchangeability.
Explicit multi-year requirements and mandatory DevSecOps/tooling experience make shortlisting highly selective.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own application security integration throughout the Software Development Life Cycle (SDLC) including threat modeling, secure design reviews, and guidance to development teams.
Develop and automate security self-service and vulnerability management solutions to consolidate, aggregate, and notify security findings to stakeholders.
Collaborate with software development teams and third-party organizations to address security, privacy, and compliance requirements in software products.
5+ years of experience in application security with relevant testing tools such as DAST (Burp Suite, OWASP Zap, Invicti, AppScan), SAST/SCA (Fortify, Checkmarx, Coverity, Semgrep, OWASP Dependency Check, Mend, Blackduck), or Attack Surface Management (OWASP Amass, Spiderfoot, CyCognito).
3+ years experience with Python, Bash, and/or PowerShell scripting.
3+ years experience in DevSecOps with integration of security solutions into CI-CD pipelines and automated tooling orchestration.
Work Experience Required: 5+ years in application security and relevant testing tools.
Candidates with a security-oriented software engineering background experienced in agile development and microservice architectures.
Individuals with experience partnering closely with development and systems engineers on impactful security initiatives and engineering-focused problem solving.
Candidates familiar with DevSecOps cultural mindsets and engineering approaches to complex security challenges in software development.