30 Sep
|
Ampstek
|
Sydney
Role: Business Analyst – AppSec / DevSecOps / GitLab SAST & SCA
Experience: 6–10 years overall BA experience, with 2–3+ years in Cybersecurity, Application Security, DevSecOps, or Platform Engineering.
Role Purpose
We are looking for a Business Analyst with robust Application Security and DevSecOps knowledge to act as the bridge between Cybersecurity, Engineering/DevOps, Platform teams, and technical SMEs.
The role will translate business and security requirements into structured requirements, rollout plans, governance processes, and implementation frameworks for GitLab SAST and SCA across GitLab SaaS and Self-Managed/On-Prem environments.
Key Responsibilities
- Conduct discovery sessions with Engineering, Platform, DevOps, and Security teams to understand the current SDLC, GitLab topology, CI/CD processes, and existing security scanning tools.
- Define functional and non-functional requirements for SAST and SCA/dependency scanning.
- Assess requirements around programming language/framework coverage, scan performance,
pipeline impact, false positives, and security scanning scope.
- Develop build-vs-buy and tool-selection matrices comparing GitLab-native SAST/SCA with third-party security scanning solutions.
- Assess differences between GitLab SaaS and GitLab Self-Managed/On-Prem environments, including version and feature limitations.
- Map GitLab vulnerability management processes with existing ITSM/ticketing platforms.
- Create user stories, functional requirements, acceptance criteria, and process documentation.
- Define requirements for pipeline integration, security exceptions/waivers, developer notifications, dashboards, and reporting.
- Support CISO-level reporting requirements, including scan coverage, vulnerability trends, MTTR, and false-positive rates.
- Maintain RAID logs, RACI matrices, stakeholder maps, and rollout plans.
#J-18808-Ljbffr
📌 Business Analyst – Application Security DevSecOps (Sydney)
🏢 Ampstek
📍 Sydney