- Solid experience in Application Security, Secure SDLC, and DevSecOps practices.
- Hands-on expertise with SAST, DAST, SCA, IAST tools such as SonarQube, Checkmarx, Veracode, Fortify, or Snyk.
- Experience in application vulnerability assessment, secure code review, and remediation of security findings.
- Good understanding of OWASP Top 10, API Security Top 10, threat modeling, and penetration testing concepts.
- Knowledge of API security, cloud security (AWS/Azure/GCP), and CI/CD security integration.
- Ability to work with development teams to implement secure coding practices and security controls.
- Familiarity with authentication protocols, vulnerability management, compliance requirements, and application security best practices.