
Lead Application Security - DevSecOps & AI-Driven Software Assurance
East West Bank2 years ago
Dallas, TX, USAStaff+
Base Salary
$120k - $180k/yr
Responsibilities
- Embed application security controls into CI/CD pipelines and collaborate with development teams on secure coding and threat modeling.
- Configure and manage GitHub Advanced Security features including secret scanning, push protection, and impact analysis.
- Conduct SAST, DAST, manual code reviews, automated code reviews, API security assessments, and vulnerability remediation.
- Analyze third-party, open-source, GitHub-hosted, and compiled software for security, dependency, contribution, and supply-chain risks.
- Perform binary decomposition and reverse engineering where appropriate to assess software behavior and embedded risks.
- Support software trust, reputation, approval, onboarding, and enterprise whitelisting processes.
- Integrate threat intelligence into software risk assessments and reassess approved software when threat conditions change.
- Support WAF policy management, application-layer threat monitoring, and penetration testing coordination with third-party vendors.
Requirements
- Proven experience in application security, DevSecOps, or software security analysis.
- Strong hands-on expertise with SAST/DAST tools, secure SDLC practices, GitHub, open-source ecosystems, and GitHub Advanced Security.
- Experience with third-party software risk analysis, software composition analysis, or reverse engineering and binary analysis.
- Familiarity with software supply-chain security and software trust-validation frameworks.
- Experience integrating threat intelligence into security decisions and understanding threat modeling, including STRIDE, and vulnerability management.
- Experience coordinating penetration tests and working with third-party vendors.
- Strong communication and stakeholder-engagement skills.
- Legal authorization to work in the United States is required.