Business Analyst will translate cybersecurity objectives into requirements and rollout plans for SAST and SCA across GitLab SaaS and Self-Managed environments. Responsibilities include stakeholder discovery, tool evaluation, vulnerability-management workflow design, user stories, governance artifacts, rollout sequencing, change management, training coordination, and adoption metrics. The role requires 6–10 years of business analysis experience, including cybersecurity, DevSecOps, or platform engineering exposure, plus familiarity with GitLab CI/CD, AppSec scanning concepts, vulnerability frameworks, and regulated-enterprise environments.
Position: Business Analyst with SAST/SCA
Role Purpose:
Act as the bridge between the cybersecurity team, engineering/DevOps teams, and the SME/AI Expert on this initiative, translating the business need (“introduce SAST and SCA across GitLab SaaS and GitLab On-Prem”) into a structured requirements, rollout, and governance framework. This requires enough working knowledge of AppSec scanning concepts and GitLab's CI/CD model to write requirements an engineer or vendor can act on without a long clarification loop
Key Responsibilities
• Run discovery across engineering, platform, and security stakeholders to map current-state SDLC, GitLab topology (SaaS groups/projects vs. Self-Managed instances), CI/CD pipeline patterns, and existing scanning tools (if any) across the telco's project portfolio.
• Document functional and non-functional requirements for SAST and SCA (dependency scanning) coverage — language/framework coverage, false-positive tolerance, scan performance/pipeline latency impact, and whether secrets/container scanning are in scope.
• Produce a build-vs-buy / tool-selection matrix comparing GitLab-native SAST/SCA (Free/Premium/Ultimate tiering) against third-party SAST/SCA tools, and identify where GitLab On-Prem version constraints affect feature availability versus SaaS.
• Define the vulnerability management workflow: finding → triage → issue → remediation MR → SLA tracking, and how this maps into GitLab's vulnerability management dashboard versus existing ITSM/ticketing tools.
• Write user stories/acceptance criteria for pipeline integration, exception/waiver processes, developer notification flows, and reporting/dashboards for CISO-level visibility.
• Own the RAID log, stakeholder RACI, and rollout sequencing plan (pilot teams → phased fleet-wide rollout across SaaS and On-Prem estates).
• Support change management: developer communication, training material coordination, and adoption metrics (scan coverage %, MTTR on findings, false-positive rate trend).
• Liaise directly with the SME and AI Expert roles to ensure requirements reflect real tool capability and constraints rather than assumptions.
Experience Level
Mid-to-Senior, 6–10 years total BA experience, with at least 2–3 years specifically in cybersecurity, DevSecOps, or platform engineering programmes. Telco or large regulated-enterprise experience is a strong plus given data governance and change-control overhead
Required Knowledge & Skills
• Working understanding of SAST vs. SCA vs. DAST vs. secrets detection — what each catches and doesn't.
• Familiarity with GitLab CI/CD concepts (pipelines, merge requests, .gitlab-ci.yml) — doesn't need to write pipeline code, but must read and reason about one.
• Understanding of GitLab licensing tiers (Free/Premium/Ultimate) and how SAST/SCA feature availability differs across them.
• Vulnerability management lifecycle and common frameworks (CVSS scoring, CWE, OWASP Top 10) at working-fluency level, not expert depth.
• Experience writing requirements/user stories for tooling or platform rollouts (not just business-process BA work).
• Strong stakeholder facilitation skills — this programme spans security, engineering, and platform teams who often have competing priorities.
• Comfortable working with technical SMEs to validate feasibility rather than dictating requirements in isolation.
Nice to Have
• Prior exposure to GitLab Self-Managed vs. SaaS migration or dual-topology environments.
Business analysis or security certifications (CBAP, Security+, or equivalent) — not mandatory but a positive signal
Similar Jobs
HR Tech • Information Technology • Professional Services • Sales • Software
Own the full sales cycle for SMB customers across APJ, including prospecting, discovery, product demonstrations, negotiation, closing, forecasting, and relationship management. Generate 30–40% of pipeline through outbound outreach, understand customer business challenges, engage decision-makers, achieve sales targets, and represent HiBob at industry events.
Top Skills:
SaaSSalesforce
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Operate and maintain telco cloud infrastructure and SDN in a 24x7 environment. Support Ericsson cloud products, OpenStack and Kubernetes/OpenShift workloads, hyperscale hardware, storage (Ceph/ScaleIO/Nexenta), datacenter networks, load balancers and firewalls. Monitor systems, perform capacity and health checks, automate tasks with Bash/Python/Ansible, and collaborate with cross-functional teams to ensure stable, secure virtualized network functions.
Top Skills:
A10AnsibleBashBsp8100CephCiscoDellDockerEricsson CeeEricsson CnisEricsson Hds8000Ericsson OmcEricsson SdnF5FortigateHpeJuniperKubernetesLinuxMirantisNagios Log ServerNexentaOdlOpenstackPluribus NetworksPythonRed HatRed Hat OpenshiftScaleioZabbixZenoss
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Operate, maintain and evolve Ericsson IMS and Nokia CS Core nodes across Sydney data centers. Perform fault management, incident resolution, upgrades, capacity planning, KPI monitoring, configuration/provisioning, change MOP development, Level 3 support and vendor escalation, and maintain documentation and knowledge-base.
Top Skills:
BgcfCapDiameterEricsson EnmEricsson Ims (P-CscfGrafanaH.248HssI-Cscf)IbcfIpv4Ipv6IsupKalixMapMegacoMgcfMgwNokia Msc-SNokia MssOnefmRtcpRtpS-CscfSbcSctpServicenowSigtranSipSip-ISlfSs7TasTrgwUnix/Linux CliVolteVowifi
What you need to know about the Sydney Tech Scene
From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.


