06 Oct
|
Ampstek
|
Sydney
Job Description
Role: Business Analyst – AppSec / DevSecOps / GitLab SAST & SCA
n
Experience: 6–10 years overall BA experience, with 2–3+ years in Cybersecurity, Application Security, DevSecOps, or Platform Engineering.
Role Purpose n
We are looking for a Business Analyst with solid Application Security and DevSecOps knowledge to act as the bridge between Cybersecurity, Engineering/DevOps, Platform teams, and technical SMEs.
n
The role will translate business and security requirements into structured requirements, rollout plans, governance processes, and implementation frameworks for GitLab SAST and SCA across GitLab SaaS and Self-Managed/On-Prem environments.
Key Responsibilities n
n
- Conduct discovery sessions with Engineering, Platform, DevOps, and Security teams to understand the current SDLC, GitLab topology, CI/CD processes, and existing security scanning tools.
n
- Define functional and non-functional requirements for SAST and SCA/dependency scanning.
n
- Assess requirements around programming language/framework coverage,
scan performance, pipeline impact, false positives, and security scanning scope.
n
- Develop build-vs-buy and tool-selection matrices comparing GitLab-native SAST/SCA with third-party security scanning solutions.
n
- Assess differences between GitLab SaaS and GitLab Self-Managed/On-Prem environments, including version and feature limitations.
n
- Map GitLab vulnerability management processes with existing ITSM/ticketing platforms.
n
- Create user stories, functional requirements, acceptance criteria, and process documentation.
n
- Define requirements for pipeline integration, security exceptions/waivers, developer notifications, dashboards, and reporting.
n
- Support CISO-level reporting requirements, including scan coverage, vulnerability trends, MTTR, and false-positive rates.
n
- Maintain RAID logs, RACI matrices, stakeholder maps, and rollout plans.
n
#J-18808-Ljbffr
📌 Business Analyst - Application Security DevSecOps (Sydney)
🏢 Ampstek
📍 Sydney