Business Analyst with SAST/SCA

Posted 4 Days Ago
Be an Early Applicant
Sydney, New South Wales, AUS
In-Office
Senior level
Information Technology • Software • Consulting
The Role
Business Analyst will translate cybersecurity objectives into requirements and rollout plans for SAST and SCA across GitLab SaaS and Self-Managed environments. Responsibilities include stakeholder discovery, tool evaluation, vulnerability-management workflow design, user stories, governance artifacts, rollout sequencing, change management, training coordination, and adoption metrics. The role requires 6–10 years of business analysis experience, including cybersecurity, DevSecOps, or platform engineering exposure, plus familiarity with GitLab CI/CD, AppSec scanning concepts, vulnerability frameworks, and regulated-enterprise environments.
Summary Generated by Built In
Position: Business Analyst with SAST/SCA

Role Purpose:
Act as the bridge between the cybersecurity team, engineering/DevOps teams, and the SME/AI Expert on this initiative, translating the business need (“introduce SAST and SCA across GitLab SaaS and GitLab On-Prem”) into a structured requirements, rollout, and governance framework. This requires enough working knowledge of AppSec scanning concepts and GitLab's CI/CD model to write requirements an engineer or vendor can act on without a long clarification loop

Key Responsibilities
•      Run discovery across engineering, platform, and security stakeholders to map current-state SDLC, GitLab topology (SaaS groups/projects vs. Self-Managed instances), CI/CD pipeline patterns, and existing scanning tools (if any) across the telco's project portfolio.
•      Document functional and non-functional requirements for SAST and SCA (dependency scanning) coverage — language/framework coverage, false-positive tolerance, scan performance/pipeline latency impact, and whether secrets/container scanning are in scope.
•      Produce a build-vs-buy / tool-selection matrix comparing GitLab-native SAST/SCA (Free/Premium/Ultimate tiering) against third-party SAST/SCA tools, and identify where GitLab On-Prem version constraints affect feature availability versus SaaS.
•      Define the vulnerability management workflow: finding → triage → issue → remediation MR → SLA tracking, and how this maps into GitLab's vulnerability management dashboard versus existing ITSM/ticketing tools.
•      Write user stories/acceptance criteria for pipeline integration, exception/waiver processes, developer notification flows, and reporting/dashboards for CISO-level visibility.
•      Own the RAID log, stakeholder RACI, and rollout sequencing plan (pilot teams → phased fleet-wide rollout across SaaS and On-Prem estates).
•      Support change management: developer communication, training material coordination, and adoption metrics (scan coverage %, MTTR on findings, false-positive rate trend).
•      Liaise directly with the SME and AI Expert roles to ensure requirements reflect real tool capability and constraints rather than assumptions.

Experience Level
Mid-to-Senior, 6–10 years total BA experience, with at least 2–3 years specifically in cybersecurity, DevSecOps, or platform engineering programmes. Telco or large regulated-enterprise experience is a strong plus given data governance and change-control overhead

Required Knowledge & Skills
•      Working understanding of SAST vs. SCA vs. DAST vs. secrets detection — what each catches and doesn't.
•      Familiarity with GitLab CI/CD concepts (pipelines, merge requests, .gitlab-ci.yml) — doesn't need to write pipeline code, but must read and reason about one.
•      Understanding of GitLab licensing tiers (Free/Premium/Ultimate) and how SAST/SCA feature availability differs across them.
•      Vulnerability management lifecycle and common frameworks (CVSS scoring, CWE, OWASP Top 10) at working-fluency level, not expert depth.
•      Experience writing requirements/user stories for tooling or platform rollouts (not just business-process BA work).
•      Strong stakeholder facilitation skills — this programme spans security, engineering, and platform teams who often have competing priorities.
•      Comfortable working with technical SMEs to validate feasibility rather than dictating requirements in isolation.

Nice to Have
•      Prior exposure to GitLab Self-Managed vs. SaaS migration or dual-topology environments.
        Business analysis or security certifications (CBAP, Security+, or equivalent) — not mandatory but a positive signal


Skills Required

  • 6–10 years of total business analyst experience
  • 2–3 years of experience in cybersecurity, DevSecOps, or platform engineering programs
  • Working knowledge of SAST, SCA, DAST, and secrets detection
  • Familiarity with GitLab CI/CD concepts, including pipelines, merge requests, and .gitlab-ci.yml
  • Understanding of GitLab Free, Premium, and Ultimate licensing tiers and feature availability
  • Working knowledge of vulnerability management, CVSS, CWE, and OWASP Top 10
  • Experience writing requirements and user stories for tooling or platform rollouts
  • Strong stakeholder facilitation skills across security, engineering, and platform teams
  • Ability to work with technical SMEs to validate feasibility
  • Telco or large regulated-enterprise experience
  • Exposure to GitLab Self-Managed and SaaS migration or dual-topology environments
  • CBAP, Security+, or equivalent certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
120 Employees
Year Founded: 2016

What We Do

XPT Software Australia Pty Ltd is a technology consulting and software services company serving clients across banking, financial services and insurance, telecommunications, mining, retail, energy, and manufacturing. It provides software development, IT management consulting, business analysis, project and program management, infrastructure support, and offshore development through onsite-offshore delivery. The company also works with cloud computing, big data, mobile applications, UI/UX, algorithms, and IoT.

Similar Jobs

Square Logo Square

Account Executive

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
Newcastle, New South Wales, AUS
12000 Employees
198K-297K Annually

Dynatrace Logo Dynatrace

Enterprise Account Manager

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
Sydney, New South Wales, AUS
5600 Employees
Remote or Hybrid
3 Locations
175633 Employees

Atlassian Logo Atlassian

Architect

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Sydney, New South Wales, AUS
11000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account