Job description:
We are looking for an Application Security expert to ensure a high level of security of the applications:
• To mainly ensure that developers’ DevSecOps activities related to SAST and SCA are done according to the security policies;
• To Identify global gaps and propose remediation strategy;
• To contribute to security frameworks improvements.
Main Tasks:
- Check how developers work with Fortify and Nexus IQ: alignment with development’s lifecycle, coverage of the scans;
- Check if findings are properly treated (vulnerabilities well remediated, no wrong false positive classification);
- Challenge the developers, support the remediation and acculturate them with Fortify, Nexus IQ and secure coding best practices;
- Develop tooling to automate as much as possible the DevSecOps effectiveness controls.