Application Security Engineering
- Lead the implementation and enhancement of enterprise Application Security programs.
- Design secure-by-default architecture for Application Security tooling.
- Define and maintain Secure SDLC practices across development teams.
- Establish security governance and technical standards for application security assessments.
- Drive security improvements across up-to-date software development environments.
SAST & SCA/FOSS Program Management
- Own and manage enterprise Static Application Security Testing (SAST) platforms including Snyk Code.
- Manage Software Composition Analysis (SCA) and Open Source Software (FOSS) security using Black Duck and similar platforms.
- Define, review, and continuously improve SAST scanning policies, quality gates, and security baselines.
- Review scan results, validate vulnerabilities, and perform false positive analysis.
- Support onboarding of new repositories and applications into security scanning platforms.
- Drive continuous improvements and product enhancements for SAST/SCA solutions.
DevSecOps & CI/CD Security
- Integrate cybersecurity tooling into CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins).
- Design automated security scanning workflows across development pipelines.
- Build scalable DevSecOps security controls using automation.
- Collaborate with Platform Engineering teams to embed security into development workflows.
- Improve developer experience while maintaining security compliance.