Team Lead - Application Security
Core
Lead and build an application security team to secure the SDLC, triage vulnerabilities, and integrate security controls into CI/CD pipelines for METRO's global operations.
Role type
Senior IC Application Security Team Lead
Builds
Automated security controls in CI/CD, secure software delivery pipelines, and security consultancy for product teams
Domain
Retail / Wholesale / Enterprise Software Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security (SAST, SCA, DAST), CI/CD automation, vulnerability management, OWASP/ASVS expertise, scripting, Git/GitHub/GitLab, CVE/CVSS/NVD knowledge
Preferred skills
CISSP, CSSLP, enterprise environment experience, DevSecOps
Technologies
SAST, SCA, DAST, Qualys, Polaris, GitHub, GitLab, OWASP, ASVS, NVD
Responsibilities
Setup and lead application security team; Triage high/critical findings and drive mitigation; Identify and approve true/false positive vulnerabilities; Support product teams in implementing SAST/SCA in CI/CD; Provide application security consultancy; Identify security risks in application architecture and infrastructure; Contribute to target S-SDLC framework
Seniority
Senior, hands-on IC with team leadership