SME-App Security with SAST/SCA

Zoho

Sydney

On-site

AUD 150,000 - 190,000

Full time

40 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

XPT Software Australia Pty Ltd in Sydney is seeking a Senior SME-App Security engineer to own the technical design, standards and hands-on delivery of SAST/SCA capabilities across GitLab SaaS and GitLab On-Prem. This role spans secure SDLC design, vulnerability management, architecture reviews and developer enablement, focused on a single initiative for its duration.

The candidate will define the target architecture, establish scanning policies, and align security controls with OWASP ASVS and

Qualifications

  • Senior level with 8+ years in application security / secure software engineering.
  • 4–5+ years hands-on with SAST/SCA tooling and architecture review.
  • Strong knowledge of SDLC security, threat modeling and secure design.

Responsibilities

  • Own the design, standards and delivery of SAST/SCA across GitLab SaaS and On-Prem.
  • Define target-state architecture and scanning policy, thresholds and gates.
  • Review pipelines for security issues and mentor engineering teams.
  • Provide technical input for vendor evaluation and BA-authored requirements.

Skills

SAST
SCA
AppSec
CI/CD
GitLab CI
Threat modeling
Vulnerability management
Communication

Tools

GitLab SAST
GitLab Dependency Scanning
OWASP ASVS

Job description

XPT Software Australia Pty Ltd | Contract

SME-App Security with SAST/SCA

Sydney, Australia | Posted on 09/28/2026

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • We have 120+technocrats in Australia working at our clientlocations.
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description
Team: Cybersecurity — Application Security Engineering
Role Purpose

Own the technical design, standards, and hands-on delivery of SAST/SCA capability across GitLab SaaS and GitLab On-Prem. This role carries the full depth of an AppSec Specialist's skillset — secure SDLC design, vulnerability management discipline, architecture review, developer enablement — but applied narrowly and intensively to this one initiative for its duration, rather than as an ongoing cross-portfolio function.

Key Responsibilities
  • Assess current SDLC and CI/CD pipeline architecture across both GitLab SaaS and Self-Managed/On-Prem instances, including version currency on the On-Prem side.
  • Stakeholder management as there are different owners for Gitlab SaaS and Gitlab OnPrem
  • Define the target-state SAST/SCA architecture: which GitLab-native features to use (Advanced SAST, dependency scanning, container/secrets scanning if in scope), where coverage gaps exist, and whether a third-party tool is required to close them.
  • Review pipeline and repo structure for security-relevant design issues (authN/authZ patterns, trust boundaries, dependency exposure) uncovered during rollout.
  • Set scanning policy for the initiative: severity thresholds, blocking vs. non-blocking pipeline gates, exception/waiver criteria, and false-positive management approach.
  • Define secure coding standards and guardrails scanning results should be measured against (e.g., OWASP ASVS, CWE Top 25), scoped to the languages/frameworks in this rollout.
  • Design the vulnerability triage and remediation workflow, including SLAs by severity, and how findings map into existing ticketing/GRC tooling.
  • Validate feasibility of BA-authored requirements before they're finalized; provide technical input into vendor evaluation/RFP if a third-party tool is shortlisted.
  • Perform root-cause analysis on recurring finding patterns surfaced during pilot rollout, and adjust scanning configuration/rules accordingly.
  • Provide technical sign-off on rollout readiness per team/project before scanning gates go live.
  • Run secure coding and remediation training for engineering teams as scanning gates go live for their projects.
  • Build lightweight internal documentation/reference material so teams can self-serve common remediation patterns after the SME's engagement ends.
  • Document architecture decisions, policy rationale, and configuration standards in a form the client's ongoing security team can operate and extend after the fixed-term engagement concludes.
Experience Level

Senior, 8+ years in application security / secure software engineering, with at least 4–5 years hands-on with SAST/SCA tooling specifically, and prior experience in AppSec practice broadly enough to bring architecture review and developer-enablement skills, not just scanner configuration.

Required Knowledge & Skills
  • Deep working knowledge of SAST, SCA, DAST, and secrets detection — internals of how static analyzers work, not just tool operation.
  • Hands-on experience with GitLab's native security scanning (Advanced SAST, dependency scanning) across both SaaS and Self-Managed, including feature parity gaps between tiers/versions.
  • Practical experience with at least one major third-party SAST/SCA tool to inform build-vs-buy decisions credibly.
  • CI/CD pipeline engineering fluency — able to write/review .gitlab-ci.yml and reason about pipeline performance impact.
  • Strong grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE) and experience avoiding alert fatigue in high-volume scanning environments.
  • Secure design fundamentals — authN/authZ, threat modeling (e.g., STRIDE) — sufficient to review architecture surfaced during rollout.
  • Strong communication skills for developer training and cross-team escalation handling.
  • Telco or critical-infrastructure security experience is a strong plus given regulatory and change-control constraints.
Nice to Have
  • Relevant certifications: OSCP, GWAPT, CSSLP, or equivalent.
  • Experience running a phased SAST/SCA rollout across a large multi-team, multi-repo GitLab estate (100+ projects).
  • Experience structuring handover documentation/runbooks for fixed-term security engagements.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Lead: SAST/SCA & GitLab Rollout
Senior AppSec Lead: SAST/SCA & GitLab Rollout

Zoho • Sydney

On-site
AUD 150,000 - 190,000
AI Engineer
AI Engineer

XPT Software Australia Pty Ltd • Sydney, City of Melbourne

On-site
AUD 180,000 - 240,000
DevSecOps SME
DevSecOps SME

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 140,000 - 180,000
Devsecops Specialist
Devsecops Specialist

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 140,000 - 180,000
AI Engineer
AI Engineer

XPT Software • Sydney

On-site
AUD 120,000 - 180,000
Senior DevSecOps Engineer — Secure CI/CD Architect
Senior DevSecOps Engineer — Secure CI/CD Architect

NCS • City of Melbourne

Hybrid
AUD 150,000 - 190,000
Senior DevSecOps Engineer — Secure CI/CD Architect
Senior DevSecOps Engineer — Secure CI/CD Architect

NCS Australia • City of Melbourne

Hybrid
AUD 120,000 - 180,000
Senior DevSecOps Engineer: Secure CI/CD & AppSec Automation
Senior DevSecOps Engineer: Secure CI/CD & AppSec Automation

XPT Software • Sydney

On-site
AUD 140,000 - 190,000
AI Engineer
AI Engineer

XPT Software • City of Melbourne

On-site
AUD 150,000 - 210,000