





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Metro mid-level AppSec role at a known employer; moderate competition among qualified candidates.
Role demands AppSec-specific frameworks, supply-chain and DevSecOps expertise, limiting cross-industry transferability.
Explicit 2–4 years plus required AppSec frameworks, SBOM and tooling knowledge increases shortlisting rigidity.
Develop and deliver comprehensive application security program roadmaps, maturity assessments, and framework-aligned reports.
Create visuals and documentation for capability maturity models and strategic planning in AppSec and DevSecOps contexts.
Present executive summaries and strategic security recommendations to leadership and client stakeholders.
2 to 4 years of experience in application security, software assurance, or product security consulting.
Strong knowledge of security frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
Experience with open-source software security, including vulnerability identification and remediation in third-party components.
Familiarity with Software Bill of Materials (SBOM) standards and tools like SPDX or CycloneDX.
Background in developing or executing maturity models, capability assessments, or multi-year AppSec/DevSecOps roadmaps.
Experience with secure software development practices, SDLC, and CI/CD pipelines integration.
Experience working in consulting (preferably Big Four or boutique AppSec firms) or internal software security governance roles.