Senior Application Security Engineer

Michael Page Australia

City of Melbourne

Hybrid

AUD 180,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid working
Long-term transformation project

Job summary

Michael Page Australia is recruiting a Senior Application Security Engineer to lead secure coding implementations and integrations across enterprise DevSecOps environments. You will shape scanning strategies, mentor development teams on secure practices, and partner with Security, DevOps and Development squads.

You will drive onboarding of SAST tools (Snyk, Fortify, Checkmarx, Veracode) and define governance, runbooks, and remediation workflows while ensuring alignment with enterprise security

Qualifications

  • Enterprise security engineering experience is required.
  • Hands-on with SAST tools and secure SDLC.
  • Experience integrating tooling into GitHub, GitLab and CI/CD pipelines.
  • Strong knowledge of vulnerability management and remediation workflows.
  • Excellent communication across Security, Development and DevOps teams.

Responsibilities

  • Lead the implementation and onboarding of Secure Code Scanning platforms across the software development lifecycle.
  • Design and implement integrations with GitHub, GitLab and CI/CD pipelines for automated security scanning and policy enforcement.
  • Collaborate with development, DevOps, and security teams to define scanning strategies, remediation workflows, quality gates, and secure coding controls.
  • Identify implementation challenges, integration dependencies, developer adoption issues, and performance impacts, providing practical solutions.
  • Establish vulnerability management processes, including triage, risk prioritisation, SLA definition, and remediation tracking.
  • Develop technical standards, deployment procedures, runbooks, and governance for long-term platform adoption.
  • Provide hands-on support during implementation, testing, rollout, and stabilization while mentoring teams on secure coding.

Skills

DevSecOps
Secure coding
Security tooling
CI/CD integration
Stakeholder engagement

Tools

Snyk
Fortify
Checkmarx
Veracode

Job description

  • Hybrid environment and flexible working
  • Long-term opportunity on transformation project
About Our Client

Our client is a leading global technology consulting and services organisation that partners with enterprises to deliver large-scale digital transformation, cloud, cybersecurity, and technology modernisation initiatives. They offer a collaborative and innovative environment, providing opportunities to work on complex enterprise programs leveraging modern technologies and best-practice delivery frameworks.

Job Description

Key responsibilities:

  • Lead the implementation and onboarding of Secure Code Scanning platforms such as Snyk, Fortify, Checkmarx, or Veracode across the software development lifecycle.
  • Design and implement integrations with GitHub, GitLab and CI/CD pipelines to enable automated security scanning and policy enforcement.
  • Collaborate with development, DevOps, and security teams to define scanning strategies, remediation workflows, quality gates, and secure coding controls.
  • Proactively identify implementation challenges, integration dependencies, developer adoption issues, and performance impacts, and provide practical solutions to mitigate risks.
  • Establish vulnerability management processes, including triage, risk prioritisation, exception handling, SLA definition, and remediation tracking.
  • Develop technical standards, deployment procedures, operational runbooks, and governance processes to support long-term platform adoption.
  • Provide hands-on support during implementation, testing, rollout, and post-go-live stabilization activities while mentoring development teams on secure coding practices.
The Successful Applicant

A successful Senior Application Security Engineer should have:

  • Proven experience as an Application Security Engineer or DevSecOps Engineer in enterprise environments.
  • Hands-on experience implementing SAST tools such as Snyk, Fortify, Checkmarx, or Veracode.
  • Strong knowledge of secure coding practices, application security, and SSDLC principles.
  • Experience integrating security tooling into GitHub, GitLab, and CI/CD pipelines.
  • Expertise in vulnerability management, remediation workflows, and risk prioritisation.
  • Strong stakeholder engagement skills with the ability to work across Security, Development, and DevOps teams.
  • Excellent problem-solving abilities and a practical, delivery-focused approach.
  • Experience driving adoption of security controls and DevSecOps practices across development teams.
  • Demonstrate experience implementating similar Application Security and Secure Coding solutions in larger enterprise environments
  • Excellent communication skills to collaborate with technical teams.
What's on Offer
  • Transformation project
  • Hybrid environment and flexible working
  • Long-term opportunity with project
  • Ability to upskill and work with security and AI
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Whizdom • Sydney

On-site
AUD 130,000 - 170,000
Senior Application Security Engineer
Senior Application Security Engineer

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 140,000 - 180,000
Application Security Engineer - Sydney
Application Security Engineer - Sydney

Ayan Infotech • Sydney

On-site
AUD 130,000 - 190,000
Senior Application Security Engineer – Secure Code Scanning Implementation
Senior Application Security Engineer – Secure Code Scanning Implementation

ALOIS UK • Sydney

On-site
AUD 140,000 - 210,000
Business Analyst
Business Analyst

Michael Page Australia • Sydney

Hybrid
AUD 148,000 - 221,000
Competitive day-rate
Hybrid work arrangements
Sydney-based temporary assignments
Senior Manager of Product & Application Security
Senior Manager of Product & Application Security

Talenza • Sydney

Hybrid
AUD 212,000 - 259,000
Lead Security Engineer
Lead Security Engineer

Morgan McKinley • Sydney

On-site
AUD 140,000 - 170,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Decipher Bureau • Sydney

On-site
AUD 120,000 - 200,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Group Australia • Sydney

Hybrid
AUD 150,000 - 210,000
Lead DevSecOps & AI Security Specialist - Contract
Lead DevSecOps & AI Security Specialist - Contract

NCS • Sydney

Hybrid
AUD 180,000 - 240,000