Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this DevSecOps Specialist role.
Rezi rewrites your resume against XPT Software Australia Pty Ltd's job description. Free.

Tailor your resume to this DevSecOps Specialist role.
Rezi rewrites your resume against XPT Software Australia Pty Ltd's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the DevSecOps Specialist posting at XPT Software Australia Pty Ltd — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the DevSecOps Specialist posting at XPT Software Australia Pty Ltd — free, in seconds.
About the Role
Own the technical design, standards, and hands-on delivery of SAST/SCA capability across GitLab SaaS and GitLab On-Prem. This role requires deep AppSec Specialist skills applied intensively to this initiative.
Responsibilities
- Assess current SDLC and CI/CD pipeline architecture for GitLab SaaS and Self-Managed/On-Prem instances.
- Manage stakeholders with different ownership for GitLab SaaS and GitLab On-Prem.
- Define the target-state SAST/SCA architecture, identifying coverage gaps and potential third-party tool needs.
- Review pipeline and repo structure for security-relevant design issues.
- Set scanning policy, including severity thresholds, pipeline gates, and exception criteria.
- Define secure coding standards and guardrails based on industry benchmarks.
- Design the vulnerability triage and remediation workflow with SLAs.
- Validate requirements and provide technical input for vendor evaluation if needed.
- Perform root-cause analysis on recurring finding patterns and adjust scanning configurations.
- Provide technical sign-off on rollout readiness for teams and projects.
- Conduct secure coding and remediation training for engineering teams.
- Build internal documentation for self-service remediation patterns.
- Document architecture decisions, policy rationale, and configuration standards for ongoing operation.
Requirements
- Deep working knowledge of SAST, SCA, DAST, and secrets detection internals.
- Hands-on experience with GitLab's native security scanning (Advanced SAST, dependency scanning) on both SaaS and Self-Managed.
- Practical experience with at least one major third-party SAST/SCA tool.
- CI/CD pipeline engineering fluency, including .gitlab-ci.yml.
- Strong grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE).
- Secure design fundamentals, including authN/authZ and threat modeling.
- Strong communication skills for training and escalations.
- Telco or critical-infrastructure security experience is a strong plus.
Skills
- SAST
- SCA
- DAST
- Secrets Detection
- GitLab Native Security Scanning
- CI/CD Pipeline Engineering
- Vulnerability Scoring
- Secure Design
- Communication
Experience Level
- Senior
- 8–12+ years in application security / secure software engineering
- 4–5 years hands-on with SAST/SCA tooling
- Prior experience in AppSec practice broadly