Manage GitHub Advanced Security for repository security monitoring.
Configure and maintain CodeQL-based SAST scans to detect code-level vulnerabilities.
Enable and manage Dependabot for continuous monitoring of open-source dependencies (SCA).
Monitor and review security alerts from CodeQL and Dependabot across repositories.
Provide recommendations for remediation of identified vulnerabilities.
Ensure security scanning coverage across designated GitHub repositories (e.g., master branches).
Maintain configurations and reporting related to application security testing.
Application and Testing-Scope:
Scanning of software before software package is released in production workplace GCP hosted applications
Scanning of software before software is released on Company Portal e.g. Adobe, chrome etc.
Testing of application performance/compatibility with endpoint security tools and devices e.g. ZS, Entra MDE, e.g. iPad, Android phones, laptops etc.
DevSecOps process definition and lifecycle CI/CD pipeline management from security perspective
Coordinate with ArmorCode vendor team for escalations, product enhancements, and roadmap alignment.