The Role
Lead application security by shifting left: perform threat modeling and secure design reviews, deploy SAST/DAST/SCA/secrets scanning, integrate security into CI/CD, run code reviews, track remediation SLAs, maintain asset inventory, lead Security Champions, train developers, and evaluate security tools and automation.
Summary Generated by Built In
Responsibilities
- Shift left” security efforts to build security into the software development lifecycle:
- Conduct secure design reviews and threat modeling to identify and prioritize risks, attack surfaces, and vulnerabilities
- Deploy and operationalize static (SAST), dynamic (DAST), dependency (SCA) and secrets scanning
- Work with Platform DevOps team to build and maintain security automation tools to seamlessly embed inline security checks into CI/CD pipelines
- Partner with Platform DevOps to help design secure-by-default architectures and workflows
- Assist with application security code reviews of source code changes and advise developers on remediating vulnerabilities following secure coding practices
- Establish and track SLA governance to ensure security findings are identified, prioritized, and remediated.
- Maintain application asset inventory.
- Lead the Security Champions Program to build security-minded culture amongst developers and IT Operations teams.
- Act as a trusted advisor and partner for development and cross-functional project teams, providing actionable guidance to address security.
- Help with training on secure coding practices, empowering teams to proactively prevent vulnerabilities.
- Evaluate and implement security tools and automation solutions to enhance the security posture of applications and streamline security processes.
PROFILE
- Bachelor's degree in Computer Science, Information Security, or related professional experience.
- Have 3+ years of hands-on experience in application security, including securing cloud-based and containerized environments.
- Experience performing secure code reviews and interpreting SAST/SCA/DAST results.
- Strong experience with modern development workflows, including CI/CD pipelines, using Azure Pipelines and GitHub Actions.
- Working knowledge of the OWASP Top 10 for web applications and APIs and how to apply the standard to minimize security risk.
- In-depth understanding of vulnerabilities and secure coding practices.
- Hands-on experience with security tools like Snyk, Veracode, Burpsuite or similar.
- Familiarity with cloud platforms (AWS, Azure) and containerization (Docker, Kubernetes).
- Proficiency in programming languages like Python, Java, or C# is preferred.
- Have empathy, collaboration skills, and a learning mindset to work cross-functionally with engineers of all levels to build security into the product life cycle.
- Possess broad security knowledge to connect the dots across domains and identify holistic ways to lower the overall threat surface.
- Have the ability to distill complex security concepts into clear actions and drive consensus with minimum supervision.
- Demonstrated success in partnering with developers to integrate security.
Skills Required
- Bachelor's degree in Computer Science, Information Security, or equivalent professional experience
- 3+ years of hands-on experience in application security, including cloud-based and containerized environments
- Experience performing secure code reviews and interpreting SAST/SCA/DAST results
- Strong experience with CI/CD pipelines using Azure Pipelines and GitHub Actions
- Working knowledge of the OWASP Top 10 for web applications and APIs
- In-depth understanding of vulnerabilities and secure coding practices
- Hands-on experience with security tools like Snyk, Veracode, Burpsuite or similar
- Familiarity with cloud platforms (AWS, Azure) and containerization (Docker, Kubernetes)
- Proficiency in programming languages like Python, Java, or C#
- Ability to lead Security Champions program and partner with development teams
- Ability to distill complex security concepts into clear actions and drive consensus
- Demonstrated success in partnering with developers to integrate security
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Photon.com has emerged as one of the world’s largest and fastest-growing Digital Agencies. We work with 40% of the Fortune 100 on their Digital initiatives and are known for our ability to integrate Strategy Consulting, Creative Design, and Technology at scale. Please visit www.photon.com to learn more about us, how we work, and our customer case studies. Digital Transformation Starts Here.








