Hands-on experience with leading SAST and DAST tools (e.g., Checkmarx, Veracode, Fortify, Burp Suite, OWASP ZAP).
Strong understanding of secure software development lifecycle (SSDLC) principles and OWASP Top 10 vulnerabilities.
Experience integrating security testing into CI/CD pipelines and cloud (e.g., Jenkins, Azure DevOps, GitLab CI).
Ability to interpret and communicate vulnerability findings and remediation steps to technical and non-technical stakeholders.
Familiarity with both black-box (DAST) and white-box (SAST) testing methodologies.
Excellent collaboration, communication, and documentation skills.
Required Skills
Experience participating in or conducting security architecture reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
Proficiency in performing threat modeling exercises (e.g., using STRIDE, PASTA, or other frameworks) to systematically identify, document,
and prioritize potential threats and attack vectors in applications and systems.
Skill in translating threat model findings into actionable SAST/DAST test cases and ensuring that identified threats are adequately tested and mitigated.
Qualification
Bachelor's degree or higher in Computer Science, or equivalent experience.
Security certifications such as CSSLP, CEH, or similar.
Experience with cloud-native application security and container security.
Knowledge of regulatory and compliance requirements related to application security.
Positive to have:
Experience participating in or conducting security architecture reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
Proficiency in performing threat modeling exercises (e.g., using STRIDE, PASTA, or other frameworks) to systematically identify, document, and prioritize potential threats and attack vectors in applications and s