Key Responsibilities :
Security Leadership & Governance :
- Act as the single point of contact for all application security initiatives within the organization. Proactively assess security gaps, develop innovative solutions, and drive DevSecOps transformation to enhance resilience and efficiency.
- Act as the primary liaison between development and cybersecurity teams to ensure seamless integration of security into the DevOps pipeline Schedule and monitor regular scans across codebases and ensure coverage across all relevant repositories and languages.
- Review scan results, prioritize findings, and coordinate with development teams for remediation and provide guidance on false positives and secure coding practices.
- Establish and maintain Secure SDLC practices in collaboration with engineering teams.
- Provide actionable security recommendations for application security vulnerability. Collaborate with compliance teams to support audits
Technical Responsibilities :
Expert in Static Application Security Testing (SAST) and Software Composition Analysis (SCA) and manual penetration testing.Manage and optimize the use of AppSec tools : SAST, DAST, SCA, RASP. Integrate security tools into CI / CD pipelines (e.g., Azure DevOps, GitLab CI / CD, Jenkins).Drive vulnerability triage and remediation with engineering teams. Analyze third-party components and APIs for security risks.Training & Awareness :
Conduct secure coding workshops, OWASP Top 10 training, and awareness sessions.
Required Skills & Experience :
10+ years of experience in application security / engineering. Deep understanding of OWASP Top 10, CWE, CVE, and common attack vectors (XSS, SQLi, CSRF, etc.).Strong knowledge of application architectures (web, mobile, APIs, microservices). Hands-on experience with security tools (SAST, DAST, SCA, RASP, WAF, etc.).Proficiency in at least one programming language (Java, .NET, Python, Node.js, etc.). Familiarity with DevSecOps pipelines and security automation.