Responsibilities:
- Implement and maintain Application Security Testing (AST) tools (SAST, DAST, IAST, SCA, etc.) to identify code and dependency vulnerabilities during the software development lifecycle.
- Implement and maintain Application Security Posture Management (ASPM) tools to centralize and deduplicate findings from multiple solutions and integrate into software development processes.
- Provide first-line user support: resolve false positives, guide remediation, and evaluate security exception requests.
- Integrate security tooling with CI/CD pipelines.
- Develop detailed reports on security findings and remediation efforts.
- Apply high proficiency across application security, software design/development, containerization, and cloud environments.
- Communicate security risks and evangelize secure development practices.
- Triage security risks at scale across diverse application development environments and business units.
Required Qualifications:
- Bachelorโs (7 years) or Masterโs (6 years); PhD (2 years) in pharmaceutical industry preferred.
- Experience in application security and software development.
- Experience implementing/administering/supporting AST tools (SAST/DAST/IAST/SCA).
- Secure coding knowledge across multiple languages (esp. Java, Node.js).
- Experience integrating security testing into CI/CD pipelines.
- Knowledge of application security principles and vulnerabilities (OWASP Top 10, CWE) and mitigations.
- Experience scaling DevSecOps in large organizations.
- Experience implementing DevSecOps in AWS and Azure.
- Experience with Infrastructure as Code (Terraform and/or CloudFormation).
- Ability to communicate technical findings to technical and non-technical stakeholders.
- Principal-engineer capability; creative problem solving and championing new technologies.
- Excellent written/oral English communication (e.g., presenting at conferences).
- Experience coaching junior engineers.
Preferred Qualifications:
- Experience consolidating findings from multiple sources into developer workflows/tracking systems.
- Experience administering Snyk and Endor Labs.
- Experience integrating CSPM with application security pipelines.
- Experience automating workflows with Python.
- Experience adding logging to DevSecOps pipelines.
- Experience partnering with vulnerability/risk management teams.
- 5+ years appsec/software dev; 3+ years AST tooling support.