• 10+ years of Information Security, Application Security, Secure Software Development, or Technology Risk Management experience.
• 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management.
• Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing.
• Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE).
• Experience with Checkmarx One or comparable enterprise application security testing platforms.
• Ability to evaluate, validate, and adjudicate complex SAST, SCA, API Security, and related application security findings using risk-based analysis.
• Experience identifying false positives, exploitability constraints, compensating controls, and appropriate risk treatment strategies.
• Strong understanding of modern application architectures, APIs, microservices, cloud-native technologies, and DevSecOps practices.
• Experience evaluating application security controls across cloud, SaaS, PaaS, distributed, and on-premises environments.
• Strong knowledge of NIST, ISO, PCI DSS, and related security frameworks.
• Ability to communicate technical security findings, risk decisions, and remediation guidance to both technical and non-technical stakeholders.
• Strong analytical, problem-solving, stakeholder management, and risk assessment skills.