Required Qualifications
- 10+ years in Application Security / Software Security
- Able to drive/evaluate requests independently, minimal hand-holding
- Hands-on SAST tooling experience (not vendor-specific)
- CI/CD pipeline integration experience
- GitLab platform experience (current SAST environment)
- Artifactory / JFrog experience
Preferred Qualifications:
- DAST and SCA experience (SAST is immediate need; these are next 2-3 month additions)
- Familiarity with scanners like Polaris, OWASP ZAP (tools rotate — general literacy matters more than a specific product)
- Experience using AI for security automation/remediation
- Strong cross-functional communication — this role guides developers through remediation options directly