





Metro mid-level role with specialized AppSec tools and CI/CD but common developer background yields medium competition.
Requires specialized application and product security expertise, limiting transferability from general software engineering roles.
Mandatory 5+ years, appsec tooling, CI/CD integration, and regulatory compliance imply high shortlisting strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Integrate and embed security practices across the Software Development Life Cycle (SDLC) from design through product release.
Conduct comprehensive security assessments including code reviews, various security testing methods (SAST, SCA, DAST, fuzz testing, penetration testing) and vulnerability analysis to identify and remediate product security risks.
Collaborate directly with development, QA, DevOps, and product teams to implement security controls, automate testing, support threat modelling, maintain SBOMs, and ensure regulatory compliance (e.g., EU Cyber Resilience Act).
Bachelor’s or master’s degree in Cyber Security, Computer Science, Information Security, Software Engineering, or related technical discipline.
5+ years of experience in software development, application security, or product security.
Strong hands-on programming skills in at least one language: C/C++, Java, Python, or JavaScript.
Experience with security testing tools (SAST, SCA, DAST, fuzzing, penetration testing) and familiarity with CI/CD pipelines and DevSecOps practices.
Experienced in embedding security seamlessly within agile product development and CI/CD workflows to enable early vulnerability detection and rapid remediation.
Strong collaborative approach working closely with diverse product, engineering, QA, and security teams to enforce security best practices and regulatory standards.
Well-versed in application and product security fundamentals including vulnerability classes (OWASP Top 10, CWE), threat modelling, risk assessment, and software composition analysis.