15 Sep
|
NCS Australia
|
Sydney
15 Sep
NCS Australia
Sydney
Job Description
We are seeking a highly specialized Lead DevSecOps & AI Security Specialist to bridge business analysis, security architecture, and hands-on application security tooling across our enterprise software delivery pipelines.
This role is ideal for a senior practitioner who combines the technical capability of a DevSecOps Subject Matter Expert (SME) with the analytical depth to drive security standards, AI-driven governance, and end-to-end policy implementation at scale.
Core Focus Areas
1. DevSecOps SME & Code Scanning Implementation
- Hands-on Tooling Roll-Out: Lead the end-to-end implementation, configuration, and integration of code scanning platforms across the enterprise—going beyond operational usage to build the toolchain architecture from the ground up.
- Security Testing Standards: Define, implement, and enforce SAST, SCA, and DAST scanning standards directly within automated CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Azure DevOps).
- Operational Rules & Triage: Establish baseline scanning rulesets, triage workflows, vulnerability remediation SLAs, and false-positive reduction strategies for development squads.
2. AI-Driven DevSecOps Governance
- AI Security Architecture:
Pioneer and implement DevSecOps governance frameworks and security guardrails utilizing AI capabilities and LLM tools.
- Automated Enforcement: Establish automated policy enforcement, AI-assisted code remediation guidance, and smart threat modeling workflows for software engineering teams.
- AI Tooling Standards: Define policies and standards for secure AI deployment, AI code-assistant usage, and data privacy governance within up-to-date development environments.
3. Technical Business Analysis & Delivery
- Requirements & Governance: Translate complex application security, compliance, and regulatory requirements into actionable user stories, engineering epics, and implementation roadmaps.
- Cross-Squad Collaboration: Work closely with software engineers, security architects, DevOps specialists, and product leaders to embed security seamlessly into the SDLC.
- Runbooks & Metrics: Develop operational runbooks, technical governance documentation, and metrics dashboards to monitor platform adoption, pipeline health, and overall security posture.
📌 Lead DevSecOps & AI Security Specialist - Contract (Sydney)
🏢 NCS Australia
📍 Sydney