The Role
Lead enterprise implementation of secure code scanning platforms across the SDLC. Integrate scanning tools with GitHub, GitLab, and CI/CD pipelines; establish security policies, quality gates, vulnerability management, remediation workflows, and governance processes. Support rollout and stabilization while mentoring development teams on secure coding practices and collaborating with DevOps and security stakeholders.
Summary Generated by Built In
Job description: Senior Application Security Engineer – Secure Code Scanning
Implementation
- Lead the implementation and onboarding of Secure Code Scanning
platforms such as Snyk, Fortify, Checkmarx, or Veracode across the
software development lifecycle.
- Design and implement integrations with GitHub, GitLab and CI/CD
pipelines to enable automated security scanning and policy enforcement.
- Collaborate with development, DevOps, and security teams to define
scanning strategies, remediation workflows, quality gates, and secure
coding controls.
- Proactively identify implementation challenges, integration dependencies,
developer adoption issues, and performance impacts, and provide practical
solutions to mitigate risks.
- Establish vulnerability management processes, including triage,
risk prioritization, exception handling, SLA definition, and remediation
tracking.
- Develop technical standards, deployment procedures, operational
runbooks, and governance processes to support long-term platform adoption.
- Provide hands-on support during implementation, testing, rollout,
and post-go-live stabilization activities while mentoring development
teams on secure coding practices.
- Demonstrated experience implementing similar Application Security
and Secure Coding solutions in large enterprise environments, with strong
knowledge of SAST, vulnerability management, SDLC, and DevSecOps
practices.
Skills Required
- Experience implementing Application Security and Secure Coding solutions in large enterprise environments
- Strong knowledge of SAST
- Strong knowledge of vulnerability management
- Strong knowledge of the software development lifecycle
- Strong knowledge of DevSecOps practices
- Experience with secure code scanning platforms such as Snyk, Fortify, Checkmarx, or Veracode
- Experience integrating security scanning with GitHub, GitLab, and CI/CD pipelines
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
XPT Software Australia Pty Ltd is a technology consulting and software services company serving clients across banking, financial services and insurance, telecommunications, mining, retail, energy, and manufacturing. It provides software development, IT management consulting, business analysis, project and program management, infrastructure support, and offshore development through onsite-offshore delivery. The company also works with cloud computing, big data, mobile applications, UI/UX, algorithms, and IoT.



.png)





