Source description
About the role
Role Summary Key Responsibilities: Embed security into CI/CD pipelines through scalable guardrails, automated security checks, and continuous improvements to developer workflows. Drive adoption of secure coding best practices across engineering teams through tooling, guidance, and direct partnership. Lead threat modeling exercises for high-risk features and current architecture patterns. Own, maintain, and tune AppSec tooling including SAST, DAST, SCA, secrets scanning, container scanning, and dependency management. Partner with DevOps to ensure automated testing integrates into build, test, and deploy workflows with high signal-to-noise and mnimal developer friction. Evaluate emerging technologies and automation opportunities to strengthen AppSec capabilities.- Ensure timely remediation through strong cross-functional partnership, driving the right balance of risk, velocity, and operational maturity. Support security reviews, pen test scoping, and remediation programs tied to GovRAMP, SOC 2, and customer requirements. Conduct manual reviews of critical code paths, APIs, backend services, and cloud components to identify security defects that automation may miss. Advise on secure design patterns for microservices, cloud-native architectures, authentication/authorization mechanisms, secrets management, and data protection.- Perform deep-dive analysis of current vulnerabilities, exploit techniques, frameworks, and supply-chain risks affecting our tech stack. Mentor engineering teams on secure design, secure coding, and up-to-date AppSec patterns. Lead internal workshops, brown bags, and knowledge-sharing sessions. Contribute to internal AppSec documentation, policies, and secure development standards. Qualifications Required: Hands-on experience with SAST, DAST, SCA, secrets scanning, container scanning, and CI/CD integration. Expertise in OWASP Top 10, ASVS, SANS CWE Top 25, and secure coding principles. Ability to perform threat modeling, code .
More at OpenGov