02 Sep
|
Randstad Digital
|
Melbourne
02 Sep
Randstad Digital
Melbourne
Application Security Lead
Location: Melbourne CBD
Summary
Prospect to join a leading enterprise organisation to own and operate an established Application Security capability across a diverse software landscape. This role is focused on driving the integration of secure coding practices, threat modeling, and automated scanning tools directly into active development workflows. Operating in a hands-on technical capacity, you will partner closely with multiple engineering teams with varying security maturity levels to establish robust standardisations, manage application risk, and uplift secure development practices without compromising delivery momentum.
Key Criteria
- 5+ years of software engineering experience, including at least 2+ years dedicated to an application security role.
- Demonstrated expertise working within DevSecOps methodologies and modern CI/CD pipeline environments.
- Hands-on experience deploying, configuring, and optimizing AppSec tooling including SAST, DAST, and SCA solutions.
- Strong technical background operating within Azure environments and managing Azure DevOps pipelines.
- Proficient in performing comprehensive secure code reviews, specifically across C#, .NET, and general web application architectures.
- Deep domain understanding of OWASP Top 10 vulnerabilities and industry-standard secure design principles.
- Proven capacity to tailor application security strategies to suit cross-functional teams with diverse security maturity levels.
- Exceptional stakeholder engagement, communication, and self-management capabilities, balancing risk mitigation with delivery context.
Key Responsibilities
- Own and operate application security end-to-end across the full Software Development Lifecycle (SDLC).
- Identify and evaluate application security risks, partnering directly with Engineering teams to facilitate timely remediation.
- Perform rigorous secure code reviews (primarily .NET) while actively fostering high-standard secure development practices.
- Lead comprehensive threat modeling sessions and perform formal security assessments across core applications and automation workflows.
- Adapt AppSec processes and controls to accommodate varying team maturity levels, achieving a balance between capability uplift, standardisation, and project delivery velocity.
- Manage and optimize AppSec tooling integration (SAST, DAST, SCA) embedded within automated CI/CD pipelines.
- Maintain end-to-end vulnerability visibility, establishing structured processes for risk prioritisation and leadership reporting.
- Formulate and enforce secure design and development standards across the broader software organization.
- Build and champion a Security Champions network across embedded engineering teams to drive decentralized security awareness.
- Provide technical mentorship to software developers, continuously raising the baseline secure coding capability.
If this sounds like you, someone you know, or you're ready for a confidential chat regarding your next career step, then apply below and/or send your email to ••••@randstaddigital.com.au. All applications will be reviewed, however due to large demand, detailed feedback may not always be possible.
📌 Application Security Lead (Melbourne)
🏢 Randstad Digital
📍 Melbourne