We are seeking an Application Security Risk & Automation Subject Matter Expert (SME) to support the automation and operationalization of Secure SDLC practices. This role will focus on improving application security processes, reducing developer friction, enhancing risk-based vulnerability management, and driving adoption of AI-assisted security workflows within a modern DevSecOps environment.
Key Responsibilities:
- Support the implementation and continuous improvement of Secure SDLC automation and application security operations
- Reduce developer friction through vulnerability validation, risk-based prioritization, and false-positive reduction
- Configure and maintain GitLab security controls, approval workflows, merge request (MR) security policies, and enforcement gates
- Implement and support AI-assisted triage, remediation recommendations, and automated findings management solutions
- Develop and maintain automation for vulnerability enrichment, correlation, routing, deduplication, and reporting
- Partner with development teams to improve remediation outcomes and increase adoption of secure development practices
- Support onboarding, integration, and operationalization of new application security tools and capabilities
- Collaborate with security, engineering, and DevOps teams to strengthen security controls throughout the software development lifecycle
Requirements
- 5+ years of experience in Application Security, DevSecOps, Security Engineering, or a related cybersecurity discipline
- Hands-on experience with security testing technologies including SAST, DAST, Software Composition Analysis (SCA), Container Security, and Secrets Detection
- Experience configuring GitLab security capabilities, approval workflows, policy enforcement, and secure development controls
- Experience integrating security tools with GitLab, ServiceNow, Jira, and enterprise reporting platforms
- Strong knowledge of application security concepts and the OWASP Top 10
- Understanding of software supply chain security, dependency management, and secure coding practices
- Proficiency with APIs, scripting, automation technologies, and AI-enabled workflows
- Strong analytical, problem-solving, and communication skills with the ability to collaborate effectively across technical teams
Preferred Qualifications:
- Relevant security certifications such as CSSLP, GSEC, Security+, CISSP, or comparable credentials
- Experience implementing security automation at scale within cloud-native or enterprise environments
- Experience driving process improvements that enhance developer experience while maintaining security standards
- Knowledge of CI/CD pipelines and modern DevSecOps practices
-
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#AlbionarcJobs#FintechJobs
#AsiaJobs#MiddleEastCareers
#TechTalent#FintechRecruitment
#FinanceOpportunities#
