2 months ago
Pune, IndiaSenior
Responsibilities
- Embed application security controls into CI/CD pipelines and provide actionable feedback to engineers.
- Investigate, remediate, and validate application security findings, including managing exceptions and false positives.
- Conduct targeted code reviews with engineers and platform teams to identify security issues early.
- Implement and maintain security controls, integrations, and automations for applications and APIs.
- Perform threat modeling to identify abuse cases, threat actors, and preventative and detective controls.
- Collaborate with the METRO Corporate Information Security engineering community to define practices, prioritize work, and execute security activities.
- Mentor engineers and raise awareness of security mandates.
Requirements
- Application security experience identifying, investigating, and remediating vulnerabilities across the SDLC.
- Hands-on experience writing and reviewing code and contributing to developer workflows such as design reviews, planning, and implementation.
- Experience designing, implementing, and improving security tooling and CI/CD integrations with a focus on reducing noise and prioritizing risk.
- Strong developer-experience focus and ability to communicate security issues clearly.
- Familiarity with monolithic and microservice-based application architectures.
- Understanding of OWASP Top 10, SAMM, ASVS, and FIRST principles.
- Comfort working with one or more programming languages such as Java, C++, Python, or JavaScript.
- Experience with LLMs, AI, and agentic coding platforms such as GitHub Copilot, Gemini, or Claude Code.
- Proven experience as a security subject-matter expert, including mentoring and raising awareness of security mandates.
