Looking for someone who has deep understanding of AppSec and has worked on AppSec for most of their career.
Lot of experience DevSecOps, Site reliability, Infra as Code, Policy as Code, Container scanning & Supply Chain Security
Hands on experience with DAST, IAST, Threat modelling
Someone having Cloud Security experience.
Good understanding & experience with Modern development shop applying DevSecOps practices
GenAI / AI development will be helpful
Multiple Cloud providers experience.
DevOps tools experience
Scripting experience
Some database experience - SQL, PostgreSQL
Certifications related to skills will be preferred
Checkmarx, Fortify, GHAS - CodeQL (No need to have all tools experiences, deep experiences on 1 tool would work)
BlackDuck, Prisma, CycloneDX, Jfrog Xray, GHAS – Secrets, GHAS - Dependabot (No need to have all tools experiences, deep experiences on 1 tool would work)
Invicti Netsparker, WebInspect, AppScan, BurpSuite, ZAP (No need to have all tools experiences, deep experiences on 1 tool would work