Application Security: Conduct security assessments of web, mobile, API, and enterprise applications to identify and mitigate vulnerabilities.
Secure Development: Support the adoption of secure coding practices and ensure security requirements are integrated into software development activities.
Vulnerability Management: Track, prioritize, and support remediation of application security vulnerabilities identified through testing exercises.
Security Testing: Coordinate and perform application security reviews, code reviews, penetration testing, and vulnerability assessments.
DevSecOps Integration: Work with development and DevOps teams to embed security controls within CI/CD pipelines and release processes.
Risk Advisory: Provide security guidance during solution design, system implementation, and technology transformation initiatives.
Compliance & Governance: Ensure applications comply with established security standards, regulatory requirements, and internal policies.
Awareness & Training: Promote application security awareness across technology teams and support secure coding education initiatives.
Qualifications & Experience
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related discipline.
Minimum of 5 years' experience in Information Security, Application Security, Secure Software Development, or a related area.
Good understanding of application security principles, secure development practices, and vulnerability management.
Experience conducting application security assessments and supporting remediation activities.
Knowledge of OWASP Top 10, API Security, Secure SDLC, and DevSecOps practices.
Relevant certifications such as CISSP, CSSLP, CEH, OSCP, CISM, or related certifications will be an advantage.
Experience within financial services or other highly regulated industries is desirable.