Security Analyst & SCA & SAST

Remote Full-time
Role & responsibilities The Senior Security Analyst (IC2) will be responsible for strengthening application security across the organisation by implementing secure development practices, performing vulnerability assessments, and driving DevSecOps initiatives. This role requires hands‑on expertise in Static Application Security Testing (SAST), Software Composition Analysis (SCA), and a strong understanding of Application Security (AppSec) and DevSecOps principles. Key Responsibilities • Application Security Testing: • Perform SAST and SCA scans for web, API, and mobile applications. • Analyze scan results, prioritise vulnerabilities, and collaborate with development teams for remediation. • DevSecOps Integration: • Embed security controls into CI/CD pipelines and automate security checks. • Drive adoption of secure coding practices and threat modelling across development teams. • Risk Management: • Conduct security reviews and validate secure architecture designs. • Maintain compliance with industry standards (OWASP, NIST, ISO 27001). • Tool Management: • Manage and optimise security tools such as HP Fortify, Checkmarx, Veracode, Burp Suite, and container security platforms. • Reduce false positives and improve scan efficiency. • Collaboration & Training: • Partner with architects, DevOps, and product teams to integrate security early in the SDLC. • Deliver training sessions on secure coding and tool usage. • Continuous Improvement: • Monitor emerging threats and recommend improvements to security processes. • Participate in POCs for new security tools and automation initiatives. Preferred candidate profile Experience & Qualification • 3-6 years of relevant experience • B.E/B. Tech or masters degree from a reputed institute with good academics history. MUST HAVE • Technical Expertise • Strong knowledge of SAST and SCA methodologies. • Hands‑on experience with tools like Fortify, Mend, Checkmarx, Veracode, SonarQube, GHAS. • Programming Knowledge • Proficiency in Java, .NET, Python, or JavaScript. • Certifications (Preferred) • CEH, CSSLP, GWAPT, or similar. • Experience • 3–6 years in application security. Skills required • SCA Management • Perform dependency scanning to identify vulnerable open‑source components. • Use tools like Mend & GHAS for SCA. • Ensure compliance with licensing and vulnerability management policies. • SAST Implementation • Configure and run SAST tools (e.g., Fortify, Checkmarx, Veracode, SonarQube). • Integrate SAST into CI/CD pipelines for automated code scanning. • Analyze scan results, prioritise vulnerabilities, and guide remediation. • Secure Development Lifecycle • Collaborate with developers to enforce secure coding standards. • Conduct code reviews and threat modelling sessions. • Governance & Compliance • Align with OWASP Top 10, NIST, and ISO 27001 standards. • Support audits and generate compliance reports. • Training & Awareness • Conduct developer training on secure coding and vulnerability remediation. Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

**Experienced Data Entry Specialist – Remote Work Opportunity at blithequark**

Remote Full-time

District Sales Manager - Remote in the state of Texas - must reside in Texas

Remote Full-time

Journeys Phone Support Representative - Seasonal (Work From Home)

Remote Full-time

**Experienced Data Entry Specialist – Remote Opportunity with Competitive Pay and Flexible Work Schedule**

Remote Full-time

Fully Licensed Catholic Mental Health Therapist

Remote Full-time

Sr Field Service Engineer HW- Nashville/ TN

Remote Full-time

Experienced Remote Data Entry Specialist – Amazon Work from Home Opportunities in the United States

Remote Full-time

Experienced Registered Nurse Med Surg / Telemetry Professional - Competitive Salary $2,205 per Week and Comprehensive Benefits Package

Remote Full-time

Business Performance Improvement - Supply Chain & Operations (Strategic Sourcing) Senior Consultant

Remote Full-time

Easy Typing Jobs for College Students (Work from Home)

Remote Full-time
← Back to Home