Application Security Engineer
Core
Strengthen enterprise Application Security programme by implementing SAST, integrating security into CI/CD pipelines, automating security workflows, and managing cloud security governance and compliance.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Enterprise SAST capabilities, automated security gates in CI/CD, secure cloud workloads, and developer enablement resources.
Domain
Software Development Lifecycle (SDLC), Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SAST platform administration, CI/CD pipeline integration, security automation scripting, vulnerability triage, secure code review, cloud security governance, compliance mapping, REST API integration, secure SDLC practices
Preferred skills
Vendor certification for SAST platforms, advanced cloud architecture knowledge
Technologies
Python, PowerShell, Bash, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, AWS, Microsoft Azure, Google Cloud
Responsibilities
Implement and optimize enterprise SAST capabilities and scanning profiles. Integrate security controls into CI/CD pipelines and define risk-based security gates. Develop automation for scanning, triage, and reporting using scripting languages. Prioritize and validate application security findings through code review. Apply cloud security governance principles to application workloads and delivery pipelines. Embed security requirements into the Secure SDLC and provide developer enablement.
Seniority
Senior, hands-on IC