SME-App Security with SAST/SCA at XPT Software Australia Pty Ltd | AU | Rezi

SME-App Security with SAST/SCA at XPT Software Australia Pty Ltd

SME-App Security with SAST/SCA

XPT Software Australia Pty Ltd · AU

5 days ago

SME-App Security with SAST/SCA

XPT Software Australia Pty Ltd · AU

6 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this SME-App Security with SAST/SCA role.

Rezi rewrites your resume against XPT Software Australia Pty Ltd's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the SME-App Security with SAST/SCA posting at XPT Software Australia Pty Ltd — free, in seconds.

About the Role

This role focuses on the technical design, standards, and delivery of SAST/SCA capabilities for GitLab SaaS and On-Prem. It requires deep AppSec expertise applied intensively to this initiative, encompassing secure SDLC design, vulnerability management, architecture review, and developer enablement.

Responsibilities

  • Assess current SDLC and CI/CD pipeline architecture for GitLab SaaS and Self-Managed/On-Prem instances.
  • Manage stakeholders across GitLab SaaS and GitLab On-Prem.
  • Define the target-state SAST/SCA architecture, identifying coverage gaps and potential third-party tool needs.
  • Review pipeline and repo structure for security design issues during rollout.
  • Set scanning policies, including severity thresholds, blocking gates, exception criteria, and false-positive management.
  • Define secure coding standards and guardrails based on OWASP ASVS and CWE Top 25.
  • Design the vulnerability triage and remediation workflow with SLAs and integration into existing tooling.
  • Validate requirements and provide technical input for vendor evaluation if a third-party tool is needed.
  • Perform root-cause analysis on recurring finding patterns and adjust scanning configurations.
  • Provide technical sign-off on rollout readiness for teams before scanning gates are active.
  • Conduct secure coding and remediation training for engineering teams.
  • Build internal documentation for self-service remediation patterns.
  • Document architecture decisions, policy rationale, and configuration standards for ongoing operational use.

Requirements

  • Senior-level experience with 8+ years in application security or secure software engineering.
  • 4-5 years of hands-on experience with SAST/SCA tooling.
  • Prior experience in AppSec practice covering architecture review and developer enablement.
  • Deep working knowledge of SAST, SCA, DAST, and secrets detection internals.
  • Hands-on experience with GitLab's native security scanning (Advanced SAST, dependency scanning) on both SaaS and Self-Managed.
  • Practical experience with at least one major third-party SAST/SCA tool.
  • CI/CD pipeline engineering fluency, including writing/reviewing .gitlab-ci.yml.
  • Strong grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE).
  • Experience avoiding alert fatigue in high-volume scanning environments.
  • Secure design fundamentals, including authN/authZ and threat modeling (e.g., STRIDE).
  • Strong communication skills for developer training and escalations.
  • Telco or critical-infrastructure security experience is a strong plus.
  • Relevant certifications: OSCP, GWAPT, CSSLP, or equivalent (Nice to Have).
  • Experience running a phased SAST/SCA rollout across a large GitLab estate (100+ projects) (Nice to Have).
  • Experience structuring handover documentation/runbooks for fixed-term security engagements (Nice to Have).

Skills

  • SAST
  • SCA
  • DAST
  • Secrets Detection
  • GitLab Native Security Scanning
  • Third-party SAST/SCA tools
  • CI/CD Pipeline Engineering
  • Vulnerability Scoring and Prioritization
  • CVSS
  • EPSS
  • CWE
  • Secure Design Fundamentals
  • Authentication (AuthN)
  • Authorization (AuthZ)
  • Threat Modeling
  • STRIDE
  • Communication Skills
  • Developer Training
  • Vendor Evaluation
  • Architecture Review
  • Developer Enablement
  • Vulnerability Management
  • Secure SDLC Design

Location

  • GitLab SaaS
  • GitLab On-Prem

Work Type

  • Full-time
  • Contract

Experience Level

  • Senior
  • 8+ years in application security / secure software engineering
  • 4-5 years hands-on with SAST/SCA tooling

About the Company

  • GitLab is a company that provides a DevOps platform.