Implement and manage AI-powered code scanning solutions to analyze source code, APIs, and dependencies for security vulnerabilities across the SDLC
Leverage AI/ML capabilities to identify complex vulnerability patterns, insecure coding practices, and hidden attack paths that traditional tools may miss
Use AI to reduce false positives, improve signal-to-noise ratio, and enable more efficient triage of security findings
Apply AI-assisted insights to perform root cause analysis and provide developers with actionable, context-aware remediation guidance
Integrate AI-enabled security scanning into CI/CD pipelines to provide real-time feedback during development and code commits
Evaluate and optimize AI models and rulesets to improve detection accuracy and alignment with enterprise risk priorities
Partner with engineering teams to embed AI-assisted code review and secure coding recommendations into developer workflows (e.g., pull requests, IDE plugins)
Monitor and measure the effectiveness of AI-based scanning through metrics such as detection rates, false positive reduction, and remediation speed
Stay current on emerging AI security tools, LLM-based code analysis, and automated remediation technologies, and drive adoption where they add value
Required Qualifications
7+ years of experience in application security, DevSecOps, or secure software engineering
Strong knowledge of OWASP Top 10 and secure coding practices
Experience with application security tools (e.g., SAST, DAST, SCA)
Experience integrating security into CI/CD pipelines
Knowledge of Ghazdo and GitHub Advance security
Proficiency in at least one programming language (e.g., Python, Java, JavaScript)