Job Description - DevSecOps Specialist

Role Purpose

Own the technical design, standards, and hands-on
delivery of SAST/SCA capability across GitLab SaaS and GitLab On-Prem. This
role carries the full depth of an AppSec Specialist's skillset — secure SDLC
design, vulnerability management discipline, architecture review, developer
enablement — but applied narrowly and intensively to this one initiative for
its duration, rather than as an ongoing cross-portfolio function.

Key
Responsibilities

•        Assess
current SDLC and CI/CD pipeline architecture across both GitLab SaaS and
Self-Managed/On-Prem instances, including version currency on the On-Prem side.

•        Stakeholder
management as there are different owners for Gitlab SaaS and Gitlab OnPrem

•        Define
the target-state SAST/SCA architecture: which GitLab-native features to use
(Advanced SAST, dependency scanning, container/secrets scanning if in scope),
where coverage gaps exist, and whether a third-party tool is required to close
them.

•        Review
pipeline and repo structure for security-relevant design issues (authN/authZ
patterns, trust boundaries, dependency exposure) uncovered during rollout.

•        Set
scanning policy for the initiative: severity thresholds, blocking vs.
non-blocking pipeline gates, exception/waiver criteria, and false-positive
management approach.

•        Define
secure coding standards and guardrails scanning results should be measured against
(e.g., OWASP ASVS, CWE Top 25), scoped to the languages/frameworks in this
rollout.

•        Design
the vulnerability triage and remediation workflow, including SLAs by severity,
and how findings map into existing ticketing/GRC tooling.

•        Validate
feasibility of BA-authored requirements before they're finalized; provide
technical input into vendor evaluation/RFP if a third-party tool is
shortlisted.

•        Perform
root-cause analysis on recurring finding patterns surfaced during pilot
rollout, and adjust scanning configuration/rules accordingly.

•        Provide
technical sign-off on rollout readiness per team/project before scanning gates
go live.

•        Run
secure coding and remediation training for engineering teams as scanning gates
go live for their projects.

•        Build
lightweight internal documentation/reference material so teams can self-serve
common remediation patterns after the SME's engagement ends.

•        Document
architecture decisions, policy rationale, and configuration standards in a form
the client's ongoing security team can operate and extend after the fixed-term
engagement concludes.

Experience
Level

Senior, 8–12+ years in application security / secure
software engineering, with at least 4–5 years hands-on with SAST/SCA tooling
specifically, and prior experience in AppSec practice broadly enough to bring
architecture review and developer-enablement skills, not just scanner
configuration.

Required
Knowledge & Skills

•        Deep
working knowledge of SAST, SCA, DAST, and secrets detection — internals of how
static analyzers work, not just tool operation.

•        Hands-on
experience with GitLab's native security scanning (Advanced SAST, dependency
scanning) across both SaaS and Self-Managed, including feature parity gaps
between tiers/versions.

•        Practical
experience with at least one major third-party SAST/SCA tool to inform
build-vs-buy decisions credibly.

•        CI/CD
pipeline engineering fluency — able to write/review .gitlab-ci.yml and reason
about pipeline performance impact.

•        Strong
grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE) and experience
avoiding alert fatigue in high-volume scanning environments.

•        Secure
design fundamentals — authN/authZ, threat modeling (e.g., STRIDE) — sufficient
to review architecture surfaced during rollout.

•        Strong
communication skills for developer training and cross-team escalation handling.

•        Telco
or critical-infrastructure security experience is a strong plus given
regulatory and change-control constraints.

Nice to Have

•        Relevant
certifications: OSCP, GWAPT, CSSLP, or equivalent.

•        Experience
running a phased SAST/SCA rollout across a large multi-team, multi-repo GitLab
estate (100+ projects).

•        Experience
structuring handover documentation/runbooks for fixed-term security
engagements.




Original job DevSecOps Specialist posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar DevSecOps Specialist Jobs in Australia

GrabJobs is the no1 job portal in Australia, connecting you to thousands of jobs fast! Find the best jobs in Australia, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.