Match Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Drive integration of automated security analysis into CI/CD pipelines across .NET, Java, and Node.js tech stacks, including administration of SAST and SCA tooling at enterprise scale.
Conduct web and desktop application security assessments, penetration testing, threat modelling, and risk assessments (IRAM2 methodology).
Support engineering teams with security design, code reviews, CI/CD pipeline security, AI integration security, and architectural reviews.
Minimum Requirements
5+ years experience in application security, software engineering, or DevSecOps.
Proven hands-on experience securing .NET, Java, and Node.js applications.
Expertise with SAST scanning at enterprise scale, SCA tooling (ideally Harness), and GitHub Actions CI/CD pipelines.
Ability to perform web and desktop penetration tests and experience with IAST and RASP tools.
Ideal Candidate Profile
Experienced in embedding security within SDLC and CI/CD pipelines for complex enterprise environments involving multiple languages and projects.
Capable of balancing hands-on technical security tasks (threat modelling, code reviews, penetration testing) with cross-functional collaboration including AI security implications.
Familiar with comprehensive application security practices including risk assessments, tool administration, and security in emerging tech such as AI.
