FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Secure Software Development and DevSecOps, with a strong focus on application security practices, threat modeling, and compliance with security frameworks. Proficient in integrating security testing tools into CI/CD pipelines and providing guidance on vulnerability remediation.
Highest-signal resume keywords
Secure Software DevelopmentDevSecOpsThreat ModelingSAST, DAST, and SCA IntegrationApplication Security Analysis
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecurityVulnerability AssessmentSecurity Architecture DesignPenetration TestingRisk MitigationSecurity ControlsStatic and Dynamic TestingSecurity AutomationCloud Security Controls.NET/Java
Soft Skills
ConsultationMentoringCommunication
Tools & Technologies
Burp SuiteFiddlerZAPWiresharkMetasploitNessusQualysKubernetesAPI GatewayWAF
Industry Keywords
OWASP Top 10SANS/CWE Top 25ISO 27001NISTCSAFFIECSECHIPAAMicrosoft SDLOWASP SAMM
Tech Stack
Tools & technologiesAWSAzureCloudJavaKubernetesSDLC.NET
About the role
Key responsibilities & impact- Serve as the primary resource for Ascensus’s application security program
- Protect, secure, and properly handle confidential Ascensus data
- Develop a comprehensive, agile, and innovative DevSecOps approach across the software development lifecycle
- Provide security consultation to scrum teams, application owners, and technology teams on security controls and secure SDLC processes
- Participate in sprint planning and decision-making sessions to embed security requirements into development practices
- Conduct application security analysis, including architecture reviews, data-flow analysis, penetration-testing support, and threat modeling
- Build and monitor compliance with application security policies, coding standards, and security controls
- Deploy and integrate services supporting SAST, DAST, and SCA functions
- Assist development teams with static and dynamic testing, triage findings, and provide remediation guidance
- Act as a trusted application security advisor and subject matter expert in secure development practices
- Perform other assigned tasks and projects
Requirements
What you’ll need- Minimum of 4 years’ experience in Secure Software Development and/or DevSecOps (preferred)
- Ability to define software security and privacy requirements
- Solid understanding of threat modeling, risk, and mitigation from internal and external threats
- Experience developing system security architecture diagrams and security architecture specifications according to security architecture standards
- Experience performing software security design reviews
- Experience integrating security testing tools into CI/CD pipelines, including SAST, DAST, and SCA
- Experience with application testing tools such as Burp Suite, Fiddler, ZAP, Wireshark, and Metasploit
- Experience configuring WAF, API Gateway, and API security tools
- Solid understanding of OWASP Top 10 and SANS/CWE Top 25
- Solid understanding of application, database, and network vulnerability testing principles
- Working knowledge of Microsoft SDL, OWASP SAMM, or BSIMM
- Experience assessing secure adoption of third-party components, including open-source or commercial software
- Understanding of information security frameworks such as ISO 27001, NIST, and CSA
- Experience operating in environments regulated against FFIEC, SEC, and/or HIPAA requirements
- Solid understanding of authentication and authorization systems
- Solid understanding of cryptographic standards, including encryption, hashing, key management, and digital signatures
- Ability to provide vulnerability remediation guidance and mentoring to product development software engineers
- Ability to translate security risks into business impact
- Experience running or managing vulnerability assessments with automated tools such as Nessus and Qualys
- Experience managing penetration testing engagements
- Understanding of privacy regulations relating to information handling and protection
- Experience with fraud detection and analysis for custom-developed applications
- Experience implementing cloud security controls following CSA or CSP best practices, including Azure and AWS
- Experience implementing and supporting security automation tools, including Kubernetes and CSP platform configuration, hardening, and monitoring
- .NET/Java experience is a plus
Benefits
Comp & perks- Equal Opportunity Employer
- Employer will never ask applicants for payment or require them to purchase equipment
