Lead SAST (Bengaluru)

Lead SAST (Bengaluru)

16 Aug
|
Daimler Trucks Innovation Center
|
Bengaluru

16 Aug

Daimler Trucks Innovation Center

Bengaluru

Responsibilities

Application Security Engineering

- Lead the implementation and enhancement of enterprise Application Security programs.

- Design secure-by-default architecture for Application Security tooling.

- Define and maintain Secure SDLC practices across development teams.

- Establish security governance and technical standards for application security assessments.

- Drive security improvements across modern software development environments.

SAST &

- SCA/FOSS Program Management

- Own and manage enterprise Static Application Security Testing (SAST) platforms including Snyk Code.

- Manage Software Composition Analysis (SCA) and Open Source Software (FOSS) security using Black Duck and similar platforms.

- Define, review, and continuously improve SAST scanning policies, quality gates, and security baselines.

- Review scan results, validate vulnerabilities, and perform false positive analysis.

- Support onboarding of current repositories and applications into security scanning platforms.

- Drive continuous improvements and product enhancements for SAST/SCA solutions.

DevSecOps &

- CI/CD Security

- Integrate cybersecurity tooling into CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins).

- Design automated security scanning workflows across development pipelines.

- Build scalable DevSecOps security controls using automation.

- Collaborate with Platform Engineering teams to embed security into development workflows.

- Improve developer experience while maintaining security compliance.

Security Tool Integration &

- Automation

- Design and implement integrations between cybersecurity platforms and enterprise tools.

- Develop automation scripts and APIs to improve security operations.

- Integrate Application Security tools with: Source Code Management

- Build Pipelines

- Issue Tracking

- Reporting Dashboards

- Vulnerability Management Platforms

- Drive end-to-end security automation initiatives.

Security Architecture





- Design scalable architecture for Application Security tooling ecosystem.

- Evaluate new security technologies and recommend enterprise adoption.

- Define architecture patterns for secure development.

- Participate in application architecture reviews from a security perspective.

- Support cloud-native and container security initiatives.

Application Security Testing

- Lead and perform technical security assessments including:

- Web Application Security Testing

- REST API Security Testing

- Thick Client Security Testing

- Secure Code Review

- Authentication &
- Authorization Testing

- Business Logic Testing

- OWASP Top 10 Validation

- API Abuse Testing

Developer Enablement

- Conduct developer security awareness sessions.

- Train Security Champions across development organizations.

- Create Secure Development Learning Paths.

- Develop secure coding guidelines and technical documentation.

- Mentor engineering teams on vulnerability remediation.

- Promote secure coding culture across global teams.

Stakeholder Management

- Work closely with: Software Development Teams

- DevOps Teams

- Enterprise Architects

- Product Owners

- Cybersecurity Teams

- Global Business Units

- Drive adoption of cybersecurity tooling and security best practices.

- Present technical recommendations to senior leadership.

Qualifications

- Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or related field.

- 8+ years of experience in Application Security, DevSecOps, or Secure Software Engineering.

- Strong hands-on experience with Snyk, Black Duck, and enterprise SAST/SCA platforms.

- Proven experience integrating security tools into enterprise CI/CD pipelines.

- Experience designing scalable security tooling architecture.

- Hands-on experience performing Web, API, and Thick Client security assessments.

- Experience reviewing and validating vulnerabilities, including false positive analysis.

- Strong understanding of modern software development practices.

- Excellent stakeholder communication and technical leadership skills.

📌 Lead SAST (Bengaluru)
🏢 Daimler Trucks Innovation Center
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead sast (bengaluru) / bengaluru