ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. Coordinate with application engineering teams on breaking-change upgrades. Integrate vulnerability gates into the SDLC where Mythos becomes central authority. Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS Solid understanding of SCA / dependency management across major language ecosystems. Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. Familiarity with SBOM standards (SPDX, CycloneDX).
Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE Prior experience in DevSecOps or AppSec in a regulated environment. Container security: image scanning, base-image hardening, distroless. Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS 5+ years DevSecOps / AppSec / engineering with security focus. Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS Bridge builder between security and engineering. Pragmatic — recognises when to upgrade vs mitigate. Strong written communication to engineering audiences.
Key Responsibilities
ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES Identify and remediate vulnerable dependenci