- Work model
- Hybrid
- Experience
- 5+ years
- Employment
- Full Time
- Compensation
- Not disclosed
- Technology signal
- 11 tags
Technology context
11Parsed from the vacancy text; ordered by relevance to this role.
Full listing
Role description
About the role
In this role you will strengthen the organization's security posture by supporting and developing solutions in close collaboration with multiple development teams. You will guide the SSDLC process on the client's side, working with development teams across all SSDLC stages - especially the vulnerability management process (remediation recommendations and re-testing) - and support solution design changes from a security perspective. A development background in Java is required, with proficiency in C# (.NET), Go , or Perl considered a plus.
Responsibilities
- Lead and grow the SSDLC together with the development team
- Review code and lead the vulnerability management process
- Assess client security maturity and define improvement roadmaps at a strategic level
- Own the technical direction for embedding security into CI/CD pipelines and engineering workflows across multiple projects
- Guide clients in adopting a risk-based vulnerability management process
- Lead threat modeling and secure architecture workshops
- Define secure development standards and guardrails across projects and teams
- Drive developer security adoption and awareness at scale
- Act as a trusted advisor and thought leader in security transformation initiatives
- Lead negotiations with clients to understand business and technical requirements
- Mentor development team members and support the bug discovery and fixing process
Requirements
- 5+ years of experience as an Application Security Engineer in SSDLC and application security assessment, including hands-on experience implementing Secure SDLC practices and leading or mentoring development teams within a product development environment
- Advanced skills in threat modeling, secure architecture reviews, and design-level security validation
- Hands-on experience with SAST and DAST tools and their integration into CI/CD pipelines
- Fluency in modern cloud-native stacks (microservices, APIs, containers, Kubernetes , public cloud platforms)
- Comfortable reviewing source code in at least one of: Java, .NET (C#), GoLang , Perl
- Strategic mindset in aligning security architecture and initiatives with business priorities, delivery timelines, compliance requirements, and risk management strategy
- Proven experience leading teams, mentoring engineers, and managing practice-level priorities and growth
- Strong influence in leading discussions with engineering managers, architects, and security leadership
- Fluent in spoken and written English
- OSCP, OSWE, OSEP, OSCE, CREST, eCPPT, eCPTX, eWPT, or eWPTX certification (nice to have)