Design, implement, and maintain application security standards, secure coding requirements, and security controls across the Software Development Lifecycle (SDLC).
Define and implement application and API security requirements, including secure architecture, authentication, authorization, and data protection controls.
Establish and operationalize application security best practices, including threat modeling, secure design reviews, and vulnerability management processes.
Configure, maintain, and optimize application security platforms and tools, including SAST, SCA, DAST, secret scanning, API security, and vulnerability management solutions.
Translate application security policies, standards, and architectural requirements into scalable security controls, governance processes, automation, and developer-focused security solutions.
Requirements:
3+ years of experience in Cybersecurity engineering
Hands-on experience with application security testing tools such as SAST, SCA, DAST, secret scanning, API security, and vulnerability management platforms.
Experience with Coverity, Black Duck, SonarQube, and GitHub Advanced Security (GHAS) or similar application security tools.
Experience defining and implementing application and API security requirements, including authentication, authorization, encryption, data protection, and secure API design.
Experience working with software development and engineering teams to identify, prioritize, remediate, and track security vulnerabilities.
Strong understanding of CI/CD, source code management, DevSecOps practices, and automated security testing.
Strong communication and collaboration skills with developers, architects, DevOps, security, and technology teams.
Education:
Bachelor s degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field.