Lead Information Security Specialist
Core
Lead Security Specialists ensure robust and secure software delivery by embedding security into the software development lifecycle, collaborating with cross-functional teams to mitigate vulnerabilities in code, systems architecture, and infrastructure.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Secure software solutions for clients via security automation and architecture
Domain
Technology consulting / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
security architecture, penetration testing, SAST/DAST integration, security automation, agile methodologies, cloud security, container security, secret management, OWASP/SANS standards
Preferred skills
consulting skills, stakeholder management, long-term risk assessment
Technologies
Checkmarx, Burp, ZAP, Fortify, Trivy, AWS, Azure, GCP
Responsibilities
Implement and refine security automation processes (SAST/DAST) in CI/CD pipelines; Conduct manual and automated security code reviews and penetration testing; Serve as a consultant to delivery teams and clients on security best practices and regulatory compliance; Work with DevOps and Cloud teams to reduce risks in code and infrastructure; Build comprehensive security strategies tailored to client contexts
Seniority
Senior, hands-on IC
