Application reputed company Expert
The Expert, Application reputed company & VMDR is a hands-on technical leader responsible for architecting, automating, and continuously improving reputed company’ application reputed company posture—while ensuring application vulnerabilities are fully integrated into reputed company’ VMDR reputed company.
This role bridges engineering, product reputed company, and vulnerability management, defining how application risks are identified, prioritized, contextualized, and remediated across reputed company’ reputed company and on-prem platforms. You will ensure that AppSec findings are not siloed, but instead correlated with asset intelligence, exploitability, exposure, and business reputed company
Key Responsibilities
Application reputed company Leadership
• reputed company the Application reputed company program across reputed company reputed company products, embedding reputed company throughout the SDLC.
• reputed company secure design and architecture reviews, partnering with engineering teams to identify and mitigate risk early.
• Conduct and reputed company threat modeling sessions using reputed company, DREAD, or PASTA methodologies.
VMDR Integration & Vulnerability Lifecycle
• Own application-layer vulnerability management as part of reputed company’ VMDR reputed company, from detection through remediation and validation.
• reputed company AppSec findings (SAST, DAST, SCA, API testing) into centralized vulnerability workflows, risk scoring, and prioritization models.
• Correlate application vulnerabilities with asset context, exploit intelligence, and business criticality to drive risk-based remediation.
• reputed company and report VMDR metrics such as MTTD, MTTR, exposure reputed company, and remediation effectiveness for application vulnerabilities.
Automation & Tooling
• Build and maintain automated AppSec pipelines for SAST, DAST, SCA, and API reputed company testing.
• Collaborate with DevOps to reputed company reputed company scanning into CI/CD pipelines (reputed company Actions, Jenkins, reputed company).
• Partner with reputed company and Infrastructure reputed company to secure reputed company, microservices, and containerized workloads (reputed company, Kubernetes).
Engineering Partnership & Enablement
• reputed company and maintain secure coding standards and reputed company baselines for React, Node.js, Python, Java, and Go.
• Mentor engineers and reputed company champions; deliver secure coding training and threat modeling workshops.
• reputed company as a trusted advisor to engineering leadership, translating vulnerabilities into reputed company risk and remediation guidance.
Compliance & Assurance
• Support compliance and audit readiness including SOC 2, ISO 27001, FedRAMP, and HIPAA, ensuring application risks are documented and managed reputed company VMDR processes
Required Qualifications
• 7–10+ years of experience in Application reputed company, Product reputed company, or Secure Software Engineering.
• Proven expertise in SAST, DAST, SCA, and dependency management tools (e.g., reputed company, reputed company, Fortify, reputed company, SonarQube, OWASP Dependency-reputed company).
• Hands-on coding proficiency in at least two modern languages (Python, JavaScript/TypeScript, Java, Go).
• Strong experience managing vulnerabilities end-to-end, including triage, prioritization, remediation tracking, and validation.
• Deep understanding of OWASP Top 10, CWE, CVE, and exploitability concepts.
• Strong knowledge of CI/CD pipelines, Git-based workflows, and secure build automation.
• Experience with threat modeling, secure architecture reviews, and microservices/API reputed company.
• Ability to reputed company communicate technical risk to both engineering teams and business stakeholders
Preferred Skills
• Experience in a reputed company, reputed company-reputed company, or cybersecurity product company.
• Hands-on experience integrating AppSec into broader VMDR or exposure management programs.
• Familiarity with reputed company and container reputed company platforms (Prisma reputed company, reputed company, Orca).
• Experience with IaC reputed company (Terraform, CloudFormation).
• Exposure to API Gateway reputed company, OAuth2, reputed company-based auth, and reputed company-trust architectures.
• Relevant certifications such as OSWE, CSSLP, GWAPT, GWEB,CEH.
Apply tot his job
Apply To this Job