Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this SME-App Security with SAST/SCA role.
Rezi rewrites your resume against XPT Software Australia Pty Ltd's job description. Free.

Tailor your resume to this SME-App Security with SAST/SCA role.
Rezi rewrites your resume against XPT Software Australia Pty Ltd's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the SME-App Security with SAST/SCA posting at XPT Software Australia Pty Ltd — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the SME-App Security with SAST/SCA posting at XPT Software Australia Pty Ltd — free, in seconds.
About the Role
This role focuses on the technical design, standards, and delivery of SAST/SCA capabilities for GitLab SaaS and On-Prem. It requires deep AppSec expertise applied intensively to this initiative, encompassing secure SDLC design, vulnerability management, architecture review, and developer enablement.
Responsibilities
- Assess current SDLC and CI/CD pipeline architecture for GitLab SaaS and Self-Managed/On-Prem instances.
- Manage stakeholders across GitLab SaaS and GitLab On-Prem.
- Define the target-state SAST/SCA architecture, identifying coverage gaps and potential third-party tool needs.
- Review pipeline and repo structure for security design issues during rollout.
- Set scanning policies, including severity thresholds, blocking gates, exception criteria, and false-positive management.
- Define secure coding standards and guardrails based on OWASP ASVS and CWE Top 25.
- Design the vulnerability triage and remediation workflow with SLAs and integration into existing tooling.
- Validate requirements and provide technical input for vendor evaluation if a third-party tool is needed.
- Perform root-cause analysis on recurring finding patterns and adjust scanning configurations.
- Provide technical sign-off on rollout readiness for teams before scanning gates are active.
- Conduct secure coding and remediation training for engineering teams.
- Build internal documentation for self-service remediation patterns.
- Document architecture decisions, policy rationale, and configuration standards for ongoing operational use.
Requirements
- Senior-level experience with 8+ years in application security or secure software engineering.
- 4-5 years of hands-on experience with SAST/SCA tooling.
- Prior experience in AppSec practice covering architecture review and developer enablement.
- Deep working knowledge of SAST, SCA, DAST, and secrets detection internals.
- Hands-on experience with GitLab's native security scanning (Advanced SAST, dependency scanning) on both SaaS and Self-Managed.
- Practical experience with at least one major third-party SAST/SCA tool.
- CI/CD pipeline engineering fluency, including writing/reviewing .gitlab-ci.yml.
- Strong grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE).
- Experience avoiding alert fatigue in high-volume scanning environments.
- Secure design fundamentals, including authN/authZ and threat modeling (e.g., STRIDE).
- Strong communication skills for developer training and escalations.
- Telco or critical-infrastructure security experience is a strong plus.
- Relevant certifications: OSCP, GWAPT, CSSLP, or equivalent (Nice to Have).
- Experience running a phased SAST/SCA rollout across a large GitLab estate (100+ projects) (Nice to Have).
- Experience structuring handover documentation/runbooks for fixed-term security engagements (Nice to Have).
Skills
- SAST
- SCA
- DAST
- Secrets Detection
- GitLab Native Security Scanning
- Third-party SAST/SCA tools
- CI/CD Pipeline Engineering
- Vulnerability Scoring and Prioritization
- CVSS
- EPSS
- CWE
- Secure Design Fundamentals
- Authentication (AuthN)
- Authorization (AuthZ)
- Threat Modeling
- STRIDE
- Communication Skills
- Developer Training
- Vendor Evaluation
- Architecture Review
- Developer Enablement
- Vulnerability Management
- Secure SDLC Design
Location
- GitLab SaaS
- GitLab On-Prem
Work Type
- Full-time
- Contract
Experience Level
- Senior
- 8+ years in application security / secure software engineering
- 4-5 years hands-on with SAST/SCA tooling
About the Company
- GitLab is a company that provides a DevOps platform.