Key ResponsibilitiesSecure Full-Stack Delivery (Embedded in Scrum Team)
- Participate actively in Scrum ceremonies including sprint planning, refinement, stand-ups, reviews, and retrospectives.
- Deliver security enhancements and remediation tasks as part of sprint commitments.
- Investigate and remediate vulnerabilities across:
- Angular, TypeScript, React, and other JavaScript front-end frameworks
- .NET / C# services, APIs, and web applications
- MS SQL Server databases and related systems
- Both legacy and modern application architectures
- Implement secure coding practices and preventive security controls, including:
- Secure input validation
- Output encoding
- CSRF protection
- Security headers
- Secure error handling
Vulnerability Remediation & Validation
- Triage, reproduce, and remediate findings from:
- Snyk (SAST, dependency security, code security)
- Invicti (DAST)
- Mend (open-source dependency governance and vulnerabilities)
- Internal and external penetration testing reports
- Drive vulnerabilities to closure with supporting evidence such as:
- Pull requests
- Test updates
- Validation scans
- Security verification results
Security Scanning & CI/CD Integration
- Ensure security scans are properly configured and consistently running across repositories, applications, and environments.
- Improve scan effectiveness by:
- Reducing false positives
- Tuning policies
- Expanding coverage for critical systems
- Build and maintain security controls within CI/CD pipelines, including security gating where appropriate.
- Establish measurable remediation timelines and service-level expectations.
Cloud & Infrastructure Security
- Partner with DevOps, SRE, and platform teams to strengthen cloud and infrastructure security, including:
- Secure IAM practices (least privilege, role-based access, access reviews)
- Secrets management and credential rotation
- Secure configuration baselines
- Encryption, logging, and monitoring
- Infrastructure-as-Code (IaC) security
- Container and Kubernetes security
- Help ensure cloud and platform changes meet security standards while supporting development velocity.
Collaboration & Technical Leadership
- Provide practical security guidance during architecture discussions, code reviews, and development activities.
- Create reusable secure components, standards, and documentation for engineering teams.
- Partner with engineering leadership on:
- Risk-based remediation planning
- Vulnerability management processes
- Security prioritization and measurable outcomes
Qualifications
- 3–5 years of experience in full-stack software engineering with strong application security experience
- Strong hands-on experience with:
- Angular / TypeScript
- React and modern JavaScript frameworks
- .NET / C#
- MS SQL Server
- Experience with security tools such as:
- Snyk
- Invicti
- Mend
- Penetration testing platforms
- Solid understanding of:
- Secure coding practices
- OWASP Top 10
- CI/CD security integration
- Cloud and infrastructure security
- Container and Kubernetes security
- Experience working in Agile/Scrum environments
- Strong troubleshooting, collaboration, and communication skills