· Checkmarx (SAST/SCA), SonarQube, Qualys WAS, Spectral, OWASP ZAP
· CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins
· Code review in Java, Python, JavaScript/TypeScript, or similar
· Threat modeling frameworks: STRIDE, PASTA, or equivalent
These are non-negotiable. If you do not meet all of these, this role is not the right fit.
· 5+ years in application security — secure SDLC, code review, vulnerability management, or AppSec tooling management
· Hands-on experience with at least 2 of: SAST, SCA, DAST, or secrets scanning tools (Checkmarx, SonarQube, Snyk, Qualys WAS, or equivalent)
· Strong understanding of CI/CD pipelines and how to integrate security checks without breaking developer velocity (GitHub Actions, Azure DevOps, Jenkins)
· Ability to review code for security issues in at least 2 programming languages (Java, Python, JavaScript/TypeScript, Go, or C#)
· Experience leading or mentoring a team — you’ll manage at least one direct report and influence a broader developer community
· Excellent communication skills — you’ll spend significant time consulting with developers who may not have security backgrounds
· Understanding of OWASP Top 10, SANS Top 25, and modern application attack patterns