





Niche SAST/SCA reduces density, but large employer, metros, and mid-level seniority increase competition.
Requires specialized application security tooling and secure-coding expertise, limiting cross-industry transferability.
Explicit 6–8 years, mandatory SAST/SCA experience and specific tool expertise make filters stringent.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Perform Static Application Security Testing (SAST) and Software Composition Analysis (SCA) on applications using various frameworks (Java, .NET, Node, Angular).
Configure, execute, and optimize SAST/SCA scans, validate results, reduce false positives, and provide remediation guidance to developers.
Integrate SAST/SCA tools with CI/CD pipelines and support vulnerability tracking and secure coding training for development teams.
6–8 years of experience in application security focusing on SAST and SCA.
Bachelor’s degree in a technical field.
Strong hands-on experience with SAST tools (e.g., Fortify, Checkmarx, Veracode) and SCA tools (e.g., Sonatype, Black Duck, Snyk).
Familiarity with CI/CD pipelines and DevSecOps integration.
Experienced in configuring and tuning SAST/SCA tools to minimize false positives and improve scan accuracy.
Proficient in analyzing code vulnerabilities across multiple languages (Java, .NET, JavaScript) and advising on secure coding fixes.
Comfortable working collaboratively with DevOps teams to embed security in CI/CD workflows and capable of delivering developer training on secure coding.