← Back to jobs

Triplecom Inc Logo
Security Engineer - Static Application Security Testing (SAST)
Posted On: 30+ days ago
Experience: 5+ years
Availability: Onsite
Openings: 1
Category: IT Security Engineer
Tenure: No Preference/Any
Related Jobs

No related jobs found

Description

You will manage security scanning operations and application onboarding within the CI/CD lifecycle.

You will own the release pipeline security integration, from onboarding applications into Veracode to troubleshooting GitLab CI/CD failures and guiding developer remediation.

Responsibilities

  • Onboard applications into Veracode by configuring scans and managing team or API account requests.
  • Troubleshoot GitLab CI/CD pipeline failures and security scan integration issues using CLI logs.
  • Manage security-related RI™Ts within ServiceNow, ensuring accurate data extraction and configuration.
  • Evaluate remediation plans and compensating controls to approve or deny risk mitigation submissions.
  • Consult with developers to help them understand identified vulnerabilities and guide effective remediation.

Required Skills

  • 5+ years of professional experience in security operations or related roles.
  • Hands-on experience with Veracode for SAST and SCA.
  • Proficiency with GitLab Ultimate and GitLab CI/CD pipelines.
  • Experience managing security requests and workflows within ServiceNow.
  • Ability to analyze command-line interface logs to troubleshoot pipeline jobs.
  • Strong understanding of Software Composition Analysis (SCA) and Static Application Security Testing (SAST) principles.
  • Ability to assess the effectiveness of technical compensating controls against security risks.

Preferred Skills

  • Experience with additional SAST/DAST tools beyond Veracode.

Education

Any Graduate

Related Jobs

No related jobs found

← Back to jobs