What you will do
Build and maintain Application Security Posture Management (ASPM) at the Company scale.
Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
Improving SAST, secrets detection rules. Keeping false positive rate low.
Identify, analyze, and remediate application security vulnerabilities.
Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
Develop and maintain secure coding guidelines for development teams.
Conduct, run threat modeling and risk assessments for new and existing applications.
Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
Serve as an application security subject matter expert to other teams.
What we look for
6+ years of experience in application security.
Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
Understanding of authentication protocols like SAML or OIDC.
Experience in conducting threat-modeling sessions.
















