





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Tier-1 employer, metro location, and mid-level experience increase candidate competition despite specialized AppSec focus.
Specialized AppSec, DevSecOps, and supply-chain security focus make background fit sensitivity high.
Explicit 2–4 years and required AppSec frameworks, SBOM, and DevSecOps experience make shortlisting high.
Develop and deliver comprehensive application security program roadmaps, maturity assessments, and framework-aligned reports.
Create visuals and documentation for capability maturity models and strategic planning related to AppSec or DevSecOps.
Prepare executive summaries and strategic recommendations tailored to leadership audiences.
2 - 4 years of experience in application security, software assurance, or product security consulting.
Strong knowledge of security frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
Familiarity with OSS security including vulnerability identification, tracking, and remediation, plus knowledge of SBOM standards/tools (e.g., SPDX, CycloneDX).
Work Experience Required: 2 - 4 years in relevant domain (application security, software assurance, or product security consulting).
Experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.
Consulting experience with Big Four firms, boutique AppSec consultancies, or internal software security governance teams is advantageous.
Background or experience in software supply chain risk management, AI/ML assurance, DevSecOps pipeline design, or software development (Java, Python, C#) within secure SDLC environments is preferred.