Get more replies from employers
Send a job-specific resume in minutes.
Jobtailor is seeking an Application Security professional to own security in the SDLC and CI/CD pipelines. You will integrate security controls (SAST/DAST/SCA), support threat modeling, and collaborate with architecture teams to ensure secure design and compliance.
You will assist developers with vulnerability triage and remediation, tune tools to minimize false positives, and contribute to audits and evidence generation. Container security and cloud-native practices are central to the role.
You’ll take ownership of work that gives us our competitive edge, including: Development and Application Security-by-Design
Integrate and operate application security controls within CI/CD pipelines, including: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Secrets detection and dependency risk scanning
Support secure SDLC practices such as: Branch protection and quality gates, Secure build and release controls, Artifact integrity and validation checks
Assist with threat modelling and secure design reviews in collaboration with architecture teams.
Support developers in vulnerability triage and remediation.
Tune security tools to reduce false positives and developer friction.
Support audit, compliance, and evidence generation activities.
Participate in security incident investigation related to application flaws.
Ensure secure, compliant approaches are the default and easiest options for development teams to adopt.
Configure and maintain security tooling integrations within CI/CD systems (e.g. GitHub Actions, GitLab CI, Jenkins, Azure DevOps) under agreed architectural standards
Ensure security controls operate consistently across teams and repositories.
Define and document DevSec security standards, patterns, and decisions.
Provide evidence and control mappings to support audits, risk assessments, and regulatory reviews.
Identify and track DevSec-related risks and technical debt, driving remediation through process improvements rather than manual controls.
Influence security outcomes through collaboration and technical leadership rather than enforcement.
Contribute to security enablement, awareness, and uplift initiatives focused on cloud-native and container security practices.
Demonstrates expertise in Application Security, including Secure SDLC practices and CI/CD pipeline security. Proficient in threat modeling, vulnerability management, and security tooling integration, with a strong focus on collaboration and enablement within cross-functional teams.