Own the technical design, standards, and hands-on
delivery of SAST/SCA capability across GitLab SaaS and GitLab On-Prem. This
role carries the full depth of an AppSec Specialist's skillset — secure SDLC
design, vulnerability management discipline, architecture review, developer
enablement — but applied narrowly and intensively to this one initiative for
its duration, rather than as an ongoing cross-portfolio function.
• Assess
current SDLC and CI/CD pipeline architecture across both GitLab SaaS and
Self-Managed/On-Prem instances, including version currency on the On-Prem side.
• Stakeholder
management as there are different owners for Gitlab SaaS and Gitlab OnPrem
• Define
the target-state SAST/SCA architecture: which GitLab-native features to use
(Advanced SAST, dependency scanning, container/secrets scanning if in scope),
where coverage gaps exist, and whether a third-party tool is required to close
them.
• Review
pipeline and repo structure for security-relevant design issues (authN/authZ
patterns, trust boundaries, dependency exposure) uncovered during rollout.
• Set
scanning policy for the initiative: severity thresholds, blocking vs.
non-blocking pipeline gates, exception/waiver criteria, and false-positive
management approach.
• Define
secure coding standards and guardrails scanning results should be measured against
(e.g., OWASP ASVS, CWE Top 25), scoped to the languages/frameworks in this
rollout.
• Design
the vulnerability triage and remediation workflow, including SLAs by severity,
and how findings map into existing ticketing/GRC tooling.
• Validate
feasibility of BA-authored requirements before they're finalized; provide
technical input into vendor evaluation/RFP if a third-party tool is
shortlisted.
• Perform
root-cause analysis on recurring finding patterns surfaced during pilot
rollout, and adjust scanning configuration/rules accordingly.
• Provide
technical sign-off on rollout readiness per team/project before scanning gates
go live.
• Run
secure coding and remediation training for engineering teams as scanning gates
go live for their projects.
• Build
lightweight internal documentation/reference material so teams can self-serve
common remediation patterns after the SME's engagement ends.
• Document
architecture decisions, policy rationale, and configuration standards in a form
the client's ongoing security team can operate and extend after the fixed-term
engagement concludes.
Senior, 8–12+ years in application security / secure
software engineering, with at least 4–5 years hands-on with SAST/SCA tooling
specifically, and prior experience in AppSec practice broadly enough to bring
architecture review and developer-enablement skills, not just scanner
configuration.
• Deep
working knowledge of SAST, SCA, DAST, and secrets detection — internals of how
static analyzers work, not just tool operation.
• Hands-on
experience with GitLab's native security scanning (Advanced SAST, dependency
scanning) across both SaaS and Self-Managed, including feature parity gaps
between tiers/versions.
• Practical
experience with at least one major third-party SAST/SCA tool to inform
build-vs-buy decisions credibly.
• CI/CD
pipeline engineering fluency — able to write/review .gitlab-ci.yml and reason
about pipeline performance impact.
• Strong
grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE) and experience
avoiding alert fatigue in high-volume scanning environments.
• Secure
design fundamentals — authN/authZ, threat modeling (e.g., STRIDE) — sufficient
to review architecture surfaced during rollout.
• Strong
communication skills for developer training and cross-team escalation handling.
• Telco
or critical-infrastructure security experience is a strong plus given
regulatory and change-control constraints.
• Relevant
certifications: OSCP, GWAPT, CSSLP, or equivalent.
• Experience
running a phased SAST/SCA rollout across a large multi-team, multi-repo GitLab
estate (100+ projects).
• Experience
structuring handover documentation/runbooks for fixed-term security
engagements.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.