Application Security Specialist
Core
Embed application security into engineering workflows and CI/CD pipelines to identify, analyze, and mitigate vulnerabilities throughout the software development lifecycle.
Role type
Application Security Specialist (DevSecOps)
Builds
Secure application development pipelines and risk mitigation strategies for global digital solutions
Domain
Information Security / DevSecOps / Software Engineering
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Web technologies (HTTP, REST APIs, microservices), Authentication/Authorization (OAuth, JWT, SSO), Vulnerability management (SQL Injection, XSS, CSRF), SAST tools (Checkmarx, Fortify), DAST tools (Burp Suite, Acunetix), SCA tools (Snyk, Black Duck), Programming languages (Java, Python, JavaScript, .NET), Threat modeling, Cloud security (AWS, Azure, GCP)
Preferred skills
Secure coding practices, Container security (Docker, Kubernetes), Infrastructure as Code (IaC) security, Bug bounty programs
Technologies
Checkmarx, Fortify, Burp Suite, Acunetix, Snyk, Black Duck, AWS, Azure, GCP, Docker, Kubernetes
Responsibilities
Translate security policies into actionable technical controls for development teams, Embed security controls into CI/CD pipelines, Perform risk-based vulnerability assessments and prioritize remediation, Conduct threat modeling for critical applications, Oversee secure code reviews and penetration testing, Define and track security KPIs (vulnerability density, MTTR)
Seniority
Mid-Senior, hands-on IC