07 Oct
|
Ampstek
|
Sydney
Job Description
Role: Business Analyst – AppSec / DevSecOps / GitLab SAST & SCA
n
Experience: 6–10 years overall BA experience, with 2–3+ years in Cybersecurity, Application Security, DevSecOps, or Platform Engineering.
Role Purpose n
We are looking for a Business Analyst with solid Application Security and DevSecOps knowledge to act as the bridge between Cybersecurity, Engineering/DevOps, Platform teams, and technical SMEs.
n
The role will translate business and security requirements into structured requirements, rollout plans, governance processes, and implementation frameworks for GitLab SAST and SCA across GitLab SaaS and Self-Managed/On-Prem environments.
Key Responsibilities n
n
Conduct discovery sessions with Engineering, Platform, DevOps, and Security teams to understand the current SDLC, GitLab topology, CI/CD processes, and existing security scanning tools.
n
Define functional and non-functional requirements for SAST and SCA/dependency scanning.
n
Assess requirements around programming language/framework coverage,
scan performance, pipeline impact, false positives, and security scanning scope.
n
Develop build-vs-buy and tool-selection matrices comparing GitLab-native SAST/SCA with third-party security scanning solutions.
n
Assess differences between GitLab SaaS and GitLab Self-Managed/On-Prem settings, including version and feature limitations.
n
Map GitLab vulnerability management processes with existing ITSM/ticketing platforms.
n
Create user stories, functional requirements, acceptance criteria, and process documentation.
n
Define requirements for pipeline integration, security exceptions/waivers, developer notifications, dashboards, and reporting.
n
Support CISO-level reporting requirements, including scan coverage, vulnerability trends, MTTR, and false-positive rates.
n
Maintain RAID logs, RACI matrices, stakeholder maps, and rollout plans.
n
J-18808-Ljbffr
📌 Business Analyst Application Security Devsecops Sydney
🏢 Ampstek
📍 Sydney