Responsibilities
- Define and mature secure SDLC and AppSec program frameworks.
- Embed secure coding practices into development and backend platform engineering.
- Lead threat modeling and high-risk security reviews for major releases.
- Implement application security testing tools (e.g. SCA, ASPM), container scanning, and secrets detection in CI/CD pipelines.
- Perform Penetration Testing and manage external penetration testing efforts
- Manage application vulnerabilities from identification to remediation.
- Provide guidance for development teams.
- Design, maintain, and enforce organization-wide paved roads and guardrails
Requirements
- 5+ years in application security, secure architecture, or related functions.
- Demonstrated ability to influence senior engineering and product leadership.
- Proven implementation of CI/CD security automation and secure coding practices.
- Strong understanding of web, API, and microservice security.
- Experience with Java, Javascript.
- Experience in Penetration Testing
Nice to Have
- Kubernetes/container security knowledge.
Work Arrangement
Remote (Worldwide) — Gibraltar, Canada, India, Isle of Man, Latvia, Malta, Romania, Serbia, Bulgaria, UAE
Additional Information
- Relocation support is not provided for this role.