XPT Software Australia Pty Ltd Logo

XPT Software Australia Pty Ltd

SME-App Security with SAST/SCA

Posted 2 Days Ago
Be an Early Applicant
In-Office
Sydney, New South Wales, AUS
Senior level
In-Office
Sydney, New South Wales, AUS
Senior level
Own the technical design and delivery of SAST/SCA capabilities across GitLab SaaS and Self-Managed environments. Assess CI/CD architecture, define scanning policies and secure coding standards, design vulnerability triage workflows, evaluate tooling, analyze recurring findings, approve rollout readiness, train developers, and document operational handoff. The role requires deep AppSec expertise, hands-on GitLab security scanning experience, secure software engineering knowledge, and strong stakeholder communication.
The summary above was generated by AI
Position: SME-App Security
 
Team: Cybersecurity — Application Security Engineering

Role Purpose
Own the technical design, standards, and hands-on delivery of SAST/SCA capability across GitLab SaaS and GitLab On-Prem. This role carries the full depth of an AppSec Specialist's skillset — secure SDLC design, vulnerability management discipline, architecture review, developer enablement — but applied narrowly and intensively to this one initiative for its duration, rather than as an ongoing cross-portfolio function.

Key Responsibilities
• Assess current SDLC and CI/CD pipeline architecture across both GitLab SaaS and Self-Managed/On-Prem instances, including version currency on the On-Prem side.
• Stakeholder management as there are different owners for Gitlab SaaS and Gitlab OnPrem
• Define the target-state SAST/SCA architecture: which GitLab-native features to use (Advanced SAST, dependency scanning, container/secrets scanning if in scope), where coverage gaps exist, and whether a third-party tool is required to close them.
• Review pipeline and repo structure for security-relevant design issues (authN/authZ patterns, trust boundaries, dependency exposure) uncovered during rollout.
• Set scanning policy for the initiative: severity thresholds, blocking vs. non-blocking pipeline gates, exception/waiver criteria, and false-positive management approach.
• Define secure coding standards and guardrails scanning results should be measured against (e.g., OWASP ASVS, CWE Top 25), scoped to the languages/frameworks in this rollout.
• Design the vulnerability triage and remediation workflow, including SLAs by severity, and how findings map into existing ticketing/GRC tooling.
• Validate feasibility of BA-authored requirements before they're finalized; provide technical input into vendor evaluation/RFP if a third-party tool is shortlisted.
• Perform root-cause analysis on recurring finding patterns surfaced during pilot rollout, and adjust scanning configuration/rules accordingly.
• Provide technical sign-off on rollout readiness per team/project before scanning gates go live.
• Run secure coding and remediation training for engineering teams as scanning gates go live for their projects.
• Build lightweight internal documentation/reference material so teams can self-serve common remediation patterns after the SME's engagement ends.
• Document architecture decisions, policy rationale, and configuration standards in a form the client's ongoing security team can operate and extend after the fixed-term engagement concludes.

Experience Level
Senior, 8+ years in application security / secure software engineering, with at least 4–5 years hands-on with SAST/SCA tooling specifically, and prior experience in AppSec practice broadly enough to bring architecture review and developer-enablement skills, not just scanner configuration.
Required Knowledge & Skills
• Deep working knowledge of SAST, SCA, DAST, and secrets detection — internals of how static analyzers work, not just tool operation.
• Hands-on experience with GitLab's native security scanning (Advanced SAST, dependency scanning) across both SaaS and Self-Managed, including feature parity gaps between tiers/versions.
• Practical experience with at least one major third-party SAST/SCA tool to inform build-vs-buy decisions credibly.
• CI/CD pipeline engineering fluency — able to write/review .gitlab-ci.yml and reason about pipeline performance impact.
• Strong grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE) and experience avoiding alert fatigue in high-volume scanning environments.
• Secure design fundamentals — authN/authZ, threat modeling (e.g., STRIDE) — sufficient to review architecture surfaced during rollout.
• Strong communication skills for developer training and cross-team escalation handling.
• Telco or critical-infrastructure security experience is a strong plus given regulatory and change-control constraints.

Nice to Have
• Relevant certifications: OSCP, GWAPT, CSSLP, or equivalent.
• Experience running a phased SAST/SCA rollout across a large multi-team, multi-repo GitLab estate (100+ projects).
• Experience structuring handover documentation/runbooks for fixed-term security engagements.


Similar Jobs

9 Hours Ago
Hybrid
Sydney, New South Wales, AUS
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Leads problem management for high-impact issues by driving root cause investigations, coordinating cross-functional resolutions, prioritizing remediation, and improving service quality and processes. The role develops reporting and data models, enhances problem management workflows using ServiceNow and scripting, and promotes collaboration across development, infrastructure, and customer support teams.
Top Skills: ItilJavaScriptPythonServicenow
Entry level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Lead financial and commercial management for Boeing’s Wedgetail Sustainment Program, including long-range planning, quarterly EAC forecasting, contract compliance, budgets, EVMS reporting, proposals, and contract variations. Present financial insights to executives and government customers, support program leadership, and manage a six-person multidisciplinary team.
Top Skills: Earned Value Management System (Evms)
16 Hours Ago
Remote or Hybrid
2 Locations
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Reviews and coordinates custody services for managed investment funds, including bank account openings and closures, AML/KYC documentation, payment processing, reconciliations, document custody, asset registers, reporting, client queries, policy adherence, and process improvement. The role also supports projects and maintains strong relationships with fund managers and banking partners.

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account