METRO AG

Team Lead - Application Security

METRO AG
Apply
over 1 year ago
Pune, IndiaStaff+

Responsibilities

  • Set up, lead, and technically steer the application security team.
  • Triage high- and critical-severity findings and drive remediation.
  • Identify, approve, and classify high-severity vulnerabilities as true or false positives.
  • Support product teams with implementing SAST and SCA in CI/CD pipelines.
  • Provide application security consultancy and technical guidance on vulnerability mitigation.
  • Identify security risks in application architecture and infrastructure and drive mitigations.
  • Contribute to secure SDLC frameworks and automated security control validation during development and deployment.
  • Support software engineering teams in addressing vulnerabilities and weaknesses.
  • Serve as the technical authority for application security engineers.
  • Contribute to Security and Privacy Engineering activities and improve application security processes and capabilities.

Requirements

  • Bachelor's degree in computer science, information technology, cybersecurity, or a related field.
  • 7+ years of relevant experience, preferably in an enterprise environment.
  • Hands-on DevSecOps experience.
  • In-depth knowledge of application security technologies and tools including SAST, SCA, and DAST.
  • Strong scripting skills and experience developing CI/CD automation.
  • Good understanding of Git concepts and vendors such as GitHub and GitLab.
  • Deep understanding of OWASP and ASVS.
  • Proficiency with vulnerability assessments and automated scanning tools such as Qualys and Polaris.
  • Understanding of CVEs, CVSS, and vulnerability databases and familiarity with NVD and CVE frameworks.
  • A master's degree or relevant certifications such as CISSP or CSSLP may be preferred.
  • Strong communication, reporting, presentation, organizational, prioritization, and interpersonal skills.

Tech Stack

Categories

METRO AG

About METRO AG

5,001-10,000 employees
Contact me