Senior Application Security Engineer

Whizdom

Sydney

On-site

AUD 140,000 - 190,000

Full time

22 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Whizdom is seeking a Senior Application Security Engineer to lead the implementation and adoption of secure code-scanning capabilities across a complex software development environment.

You will integrate automated security testing into source-control systems and CI/CD pipelines, partnering with development, DevOps and security teams to establish remediation workflows and governance. You will mentor teams and promote secure coding practices.

Qualifications

  • Demonstrated experience implementing Application Security or Secure Code Scanning solutions within large enterprise environments.
  • Strong hands-on experience with one or more platforms such as Snyk, Fortify, Checkmarx or Veracode.
  • Strong knowledge of Static Application Security Testing (SAST) and vulnerability-management practices.
  • Experience integrating security tools with GitHub, GitLab and CI/CD pipelines.

Responsibilities

  • Lead the implementation and onboarding of Secure Code Scanning platforms across complex software environments.
  • Integrate security scanning with source-control systems and CI/CD pipelines.
  • Establish scanning strategies, remediation workflows, quality gates and vulnerability-management processes.
  • Mentor development teams and promote secure coding and DevSecOps best practices.

Skills

Application Security
SAST
DevSecOps
Secure SDLC
Security tooling
Stakeholder engagement

Tools

Snyk
Fortify
Checkmarx
Veracode
GitHub
GitLab
CI/CD pipelines

Job description

We are partnering with a leading enterprise organisation to engage an experienced Senior Application Security Engineer to lead the implementation and adoption of secure code-scanning capabilities across a complex software development environment.

This opportunity will suit a hands-on Application Security professional with strong experience implementing enterprise security platforms and embedding secure coding controls throughout the software development lifecycle.

About the Role

You will lead the implementation and onboarding of a Secure Code Scanning platform, integrating automated security testing into source-control systems and CI/CD pipelines.

Working closely with development, DevOps and security teams, you will establish scanning strategies, remediation workflows, quality gates and vulnerability-management processes. You will also support implementation, testing, rollout and post-go-live stabilisation while helping development teams adopt secure coding practices.

Key Responsibilities
  • Lead the implementation and onboarding of Secure Code Scanning platforms such as Snyk, Fortify, Checkmarx or Veracode.
  • Integrate security-scanning capabilities with GitHub, GitLab and CI/CD pipelines.
  • Establish automated scanning, policy enforcement and secure coding controls across the software development lifecycle.
  • Collaborate with development, DevOps and security teams to define scanning strategies and remediation workflows.
  • Implement quality gates, exception-handling processes and vulnerability-remediation SLAs.
  • Establish vulnerability triage, risk-prioritisation and remediation-tracking processes.
  • Identify integration dependencies, developer-adoption challenges and potential performance impacts.
  • Develop technical standards, deployment procedures, operational runbooks and governance processes.
  • Provide hands-on support throughout implementation, testing, rollout and post-go-live stabilisation.
  • Mentor development teams and promote secure coding and DevSecOps best practices.
Skills & Experience
To be successful in this role, you will have:
  • Demonstrated experience implementing Application Security or Secure Code Scanning solutions within large enterprise environments.
  • Strong hands-on experience with one or more platforms such as Snyk, Fortify, Checkmarx or Veracode.
  • Strong knowledge of Static Application Security Testing (SAST) and vulnerability-management practices.
  • Experience integrating security tools with GitHub, GitLab and CI/CD pipelines.
  • Sound understanding of secure software development lifecycle principles and DevSecOps practices.
  • Experience establishing vulnerability triage, risk-prioritisation and remediation processes.
  • Ability to identify implementation risks, integration dependencies and developer-adoption challenges.
  • Experience producing technical standards, deployment documentation, runbooks and governance processes.
  • Strong stakeholder engagement skills and the ability to collaborate across development, DevOps and security teams.
  • The ability to mentor technical teams and promote practical secure coding practices.

If you are an experienced Application Security Engineer with a strong background in Secure Code Scanning, SAST and DevSecOps implementation, we’d love to hear from you

Candidates will need to be willing to undergo pre-employment screening checks, which may include identity and work rights checks, security clearance verification and any other client-requested checks

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Whizdom • Sydney

On-site
AUD 130,000 - 170,000
Senior Application Security Engineer
Senior Application Security Engineer

Michael Page Australia • City of Melbourne

On-site
AUD 180,000 - 230,000
Hybrid working
Long-term transformation project
Senior Application Security Engineer
Senior Application Security Engineer

Michael Page • Sydney

Hybrid
AUD 150,000 - 190,000
Transformation project
Hybrid environment
Long-term opportunity
+1
Senior Application Security Engineer
Senior Application Security Engineer

XPT Software • Sydney

On-site
AUD 150,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 140,000 - 180,000
Lead Secure Code Scanning Architect
Lead Secure Code Scanning Architect

XPT Software • Sydney

On-site
AUD 150,000 - 190,000
Application Security Engineer - Sydney
Application Security Engineer - Sydney

Ayan Infotech • Sydney

On-site
AUD 130,000 - 190,000
Senior Application Security Engineer – Secure Code Scanning Implementation
Senior Application Security Engineer – Secure Code Scanning Implementation

ALOIS UK • Sydney

On-site
AUD 140,000 - 210,000
Secure Code Champion: Lead App Security & DevSecOps
Secure Code Champion: Lead App Security & DevSecOps

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 140,000 - 180,000
Senior AppSec Engineer: Secure Coding & DevSecOps Lead
Senior AppSec Engineer: Secure Coding & DevSecOps Lead

Michael Page Australia • City of Melbourne

Hybrid
AUD 180,000 - 230,000
Hybrid working
Long-term transformation project