Responsibilities

  • Assist with the operation and management of application security tools, including SAST, SCA, MAST, and DAST.
  • Review vulnerability assessment results and provide remediation guidance to delivery teams.
  • Conduct reviews of application security tools and perform tuning and upgrades based on penetration testing findings.
  • Create key performance indicators (KPIs) and key risk indicators (KRIs) for the vulnerability management program and present results to senior management.
  • Participate in the development of application security and vulnerability management directives.
  • Educate development teams on the OWASP Top 10 vulnerabilities for web, mobile, and API applications.
  • Automate repetitive security tasks to improve the efficiency of existing security processes.
  • Provide ongoing production support for web and mobile application systems, including operational requests, problem analysis, resolution, escalation, and reporting.
  • Create and maintain supporting documentation.

Requirements

  • University or college diploma in Computer Science, Engineering, or an equivalent discipline.
  • CISSP, CEH, or another cybersecurity certification.
  • 2 years of experience in IT design, application design, and implementation.
  • 3 years of experience in cyber application security.
  • 1 year of experience designing automation and automating systems.
  • 2 years of software development experience using C++, Java, or .NET.
  • 1 year of experience managing application security platforms, including SAST, DAST, SCA, and mobile security tools.
  • Solid understanding of DevSecOps and Agile security concepts.
  • Hands‑on experience with SAST, SCA, DAST, and MAST tools and techniques.
  • Expert knowledge of the OWASP Top 10 for web, mobile, and APIs, as well as the SANS Top 25.
  • Demonstrated experience leading vulnerability management and analysis.
  • Experience working in an Agile environment.
  • Ability to communicate effectively with both technical and non‑technical audiences and collaborate with business partners and infrastructure teams.
  • Self‑motivated, proactive, and driven with strong problem‑solving abilities.
  • Ability to create professional Visio diagrams.
  • Security certifications such as GWAPT, GWEB, CASE, or CSSLP are considered an asset.
  • Experience interpreting penetration testing findings is considered an asset.
  • Programming knowledge is considered an asset.
  • Experience with secure development and testing of APIs, microservices, containers, and AWS cloud environments is considered an asset.
  • Knowledge of software development and vendor procurement life cycles is considered an asset.
  • Experience designing and implementing DevSecOps CI/CD pipelines is considered an asset.
  • Experience in process engineering is considered an asset.
  • Strong working knowledge of Java, J2EE, web services, and application integration technologies is considered an asset.
  • Experience designing and implementing cloud solutions is considered an asset.

Core Competencies

Demonstrates expertise in application security management, including the use of SAST, DAST, and SCA tools, while effectively communicating vulnerability assessments and remediation strategies to diverse teams. Proficient in automating security processes and developing KPIs for vulnerability management.

Highest‑signal resume keywords

  • Application Security Management
  • Vulnerability Assessment and Remediation
  • SAST, DAST, SCA Tools
  • Cybersecurity Certification (CISSP, CEH)
  • DevSecOps and Agile Security Concepts

Hard Skills

  • Application Security
  • Vulnerability Management
  • Automation Design
  • Software Development (C++, Java, .NET)
  • Penetration Testing Interpretation
  • DevSecOps CI/CD Pipeline Implementation
  • Secure API Development
  • Cloud Solutions Design
  • Visio Diagram Creation
  • Process Engineering

Soft Skills

  • Effective Communication
  • Collaboration
  • Problem‑Solving
  • Self‑Motivation
  • Proactivity

Certifications & Qualifications

  • CISSP
  • CEH
  • GWAPT
  • GWEB
  • CASE
  • CSSLP

Industry Keywords

  • OWASP Top 10
  • SANS Top 25
  • Vulnerability Management Program
  • Key Performance Indicators (KPIs)
  • Key Risk Indicators (KRIs)
  • Cyber Application Security
  • IT Design
  • Application Design
  • Operational Support
  • Security Processes

Tools & Technologies

  • SAST Tools
  • DAST Tools
  • SCA Tools
  • MAST Tools
  • AWS Cloud Environments
  • Microservices
  • Containers
  • Agile Methodologies
  • Web Services
  • Application Integration Technologies

#J-18808-Ljbffr
Similar jobs

Application Security Analyst – DevSecOps

Apply Now
Back to search page