Experience: At least 6 years in static code analysis/SAST (Static Application Security Testing), secure coding, and software development.
Technical Skills: Proficiency in static code analysis tools (e.g., SonarQube, Veracode, Checkmarx) and experience with secure code review of multiple programming languages, including:
Java
Python
.NET/C#
C/C++
Code Review Skills: Ability to read and understand source code across various programming languages and tech stacks, troubleshoot false positives, and confirm genuine issues.
Secure Coding Knowledge: Strong understanding of secure coding practices, including OWASP Top 10, SANS 25, and CWE, applicable to cloud and non-cloud environments.
Communication and Collaboration Skills: Excellent communication and interpersonal skills, with the ability to:
Effectively explain complex technical concepts to non-technical stakeholders
Collaborate with developers across multiple teams to drive remediation efforts
Facilitate training and awareness programs for developers
Work independently and as part of a distributed team
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: IT & Information SecurityRole Category: IT SecurityRole: Application Security EngineerEmployement Type: Full time