03 Oct
|
Ampstek
|
Australia
Role: Business Analyst – AppSec / DevSecOps / GitLab SAST & SCA
Experience: 6–10 years overall BA experience, with 2–3 years in Cybersecurity, Application Security, DevSecOps, or Platform Engineering.
Role Purpose
We are looking for a Business Analyst with robust Application Security and DevSecOps knowledge to act as the bridge between Cybersecurity, Engineering/DevOps, Platform teams, and technical SMEs.
The role will translate business and security requirements into structured requirements, rollout plans, governance processes, and implementation frameworks for GitLab SAST and SCA across GitLab SaaS and Self-Managed/On-Prem environments.
Key Responsibilities
Conduct discovery sessions with Engineering, Platform, DevOps, and Security teams to understand the current SDLC, GitLab topology, CI/CD processes, and existing security scanning tools.
Define functional and non-functional requirements for SAST and SCA/dependency scanning.
Assess requirements around programming language/framework coverage, scan performance, pipeline impact, false positives, and security scanning scope.
Develop build-vs-buy and tool-selection matrices comparing GitLab-native SAST/SCA with third-party security scanning solutions.
Assess differences between GitLab SaaS and GitLab Self-Managed/On-Prem settings, including version and feature limitations.
Define the vulnerability management lifecycle from finding → triage → issue → remediation → SLA tracking.
Map GitLab vulnerability management processes with existing ITSM/ticketing platforms.
Create user stories, functional requirements, acceptance criteria, and process documentation.
Define requirements for pipeline integration, security exceptions/waivers, developer notifications, dashboards, and reporting.
Support CISO-level reporting requirements, including scan coverage, vulnerability trends, MTTR, and false-positive rates.
Maintain RAID logs, RACI matrices, stakeholder maps, and rollout plans.
Required Skills
Business Analysis
Application Security / AppSec
DevSecOps
GitLab SAST & SCA
GitLab CI/CD
GitLab SaaS and Self-Managed
Vulnerability Management
SAST, SCA, DAST, Secrets Detection
CVSS, CWE, OWASP Top 10
📌 Business Analyst – Application Security Devsecops Sydney (Australia)
🏢 Ampstek
📍 Australia