At least 4 years combined work experience in software development, application security andcloud computing (e.g. AWS)
Familiar with mobile and web application programming interfaces (API) architecture (e.g. REST,SOAP, SSL/TLS)
Experience in threat modelling and able to establish threat profiles for application projects toidentify, quantify and remediate application security risks
Strong knowledge of security best practices such as OWASP Top 10, OWASP application securityverification standard
Familiar with Agile Development process, CI/CD, DevOps concepts, tools (Gitlab, Github,Ansible etc) and how automated security testing can be incorporated into CI/CI pipelines
Experience on using SAST code scanning tools such as Fortify-on-Demand, Sonarqube, etc
Track and address security vulnerabilities with timely remediation and patching processes.
Conduct security awareness training sessions
Good verbal/written communications, collaboration skills and experience interacting withvarious stakeholders
Strong analytical, problem-solving and troubleshooting skills, ability to work independently