06 Oct
|
Whizdom
|
Sydney
Job Description
We are partnering with a leading enterprise organisation to engage an experienced Senior Application Security Engineer to lead the implementation and adoption of secure code-scanning capabilities across a complex software development environment.
n
This opportunity will suit a hands-on Application Security professional with strong experience implementing enterprise security platforms and embedding secure coding controls throughout the software development lifecycle.
About the Role n
You will lead the implementation and onboarding of a Secure Code Scanning platform, integrating automated security testing into source-control systems and CI/CD pipelines.
n
Working closely with development, DevOps and security teams, you will establish scanning strategies, remediation workflows, quality gates and vulnerability-management processes. You will also support implementation, testing, rollout and post-go-live stabilisation while helping development teams adopt secure coding practices.
Key Responsibilities n
n
- Lead the implementation and onboarding of Secure Code Scanning platforms such as Snyk, Fortify, Checkmarx or Veracode.
n
- Integrate security-scanning capabilities with GitHub, GitLab and CI/CD pipelines.
n
- Establish automated scanning, policy enforcement and secure coding controls across the software development lifecycle.
n
- Collaborate with development, DevOps and security teams to define scanning strategies and remediation workflows.
n
- Implement quality gates, exception-handling processes and vulnerability-remediation SLAs.
n
- Establish vulnerability triage, risk-prioritisation and remediation-tracking processes.
n
- Identify integration dependencies, developer-adoption challenges and potential performance impacts.
n
- Develop technical standards,
deployment procedures, operational runbooks and governance processes.
n
- Provide hands-on support throughout implementation, testing, rollout and post-go-live stabilisation.
n
- Mentor development teams and promote secure coding and DevSecOps best practices.
n
Skills & Experience To be successful in this role, you will have: nn
- Demonstrated experience implementing Application Security or Secure Code Scanning solutions within large enterprise environments.
n
- Strong hands-on experience with one or more platforms such as Snyk, Fortify, Checkmarx or Veracode.
n
- Strong knowledge of Static Application Security Testing (SAST) and vulnerability-management practices.
n
- Experience integrating security tools with GitHub, GitLab and CI/CD pipelines.
n
- Sound understanding of secure software development lifecycle principles and DevSecOps practices.
n
- Experience establishing vulnerability triage, risk-prioritisation and remediation processes.
n
- Ability to identify implementation risks, integration dependencies and developer-adoption challenges.
n
- Experience producing technical standards, deployment documentation, runbooks and governance processes.
n
- Solid stakeholder engagement skills and the ability to collaborate across development, DevOps and security teams.
n
- The ability to mentor technical teams and promote practical secure coding practices.
n
n
If you are an experienced Application Security Engineer with a strong background in Secure Code Scanning, SAST and DevSecOps implementation, we’d love to hear from you
n
Candidates will need to be willing to undergo pre-employment screening checks, which may include identity and work rights checks, security clearance verification and any other client-requested checks
#J-18808-Ljbffr
📌 Senior Application Security Engineer (Sydney)
🏢 Whizdom
📍 Sydney