Role description
Conduct application security testing in order to comply with corporate policies, and regulatory requirements. Coordinate and execute application security tests, communicate the results to relevant stakeholders, and help application developers understand how to fix code security issues.
Responsibilities:
Conduct thorough application security penetration tests Work effectively with a cross-functional team to plan, execute, and communicate findings from application security testing
Work with application owners to improve their knowledge and practical application of information security best practices, including but not limited to threat assessment, vulnerability prevention and secure coding practices.
Partner with DevOps team to ensure application security tools such as SAST and DAST are performing well and generating accurate testing results.
Flexibility to change direction and manage conflicting demands.
Experience:
10 -12 years progressive Information Technology experience or equivalent specialized skills with 5+ years of application security experience.
Experience in running & administrating static analysis (SAST), dynamic analysis (DAST), and Software Composition Analysis (SCA) tools and processes
Experience in conducting and training application penetration testing
Experience in Cloud Security.
Experience and strong understanding of DevSecOps processes, tools, and integrations.
Qualifications:
Strong knowledge and ability to work with DevOps teams on the processes and integrations.
Strong web application security knowledge with thorough understanding of web, mobile, and API testing Knowledge of application security architecture and ability to perform threat modeling and risk assessments on identified applications.
Knowledge of DevSecOps processes and ability to work with the stakeholders to deliver the results for security integrations in DevOps.
Development background in .Net, Java, and/or Python a plus
Strong knowledge of Security Standards, frameworks and groups (OWASP, WASC, OSSTMM)
Knowledge of the software development lifecycle under agile environment in a large enterprise
Knowledge of database, application and Web server design
Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities Knowledge of public cloud services
Education:
Bachelor's degree in Computer Science, Information Technology or equivalent
Advanced degree preferred
Certifications including GWAPT, GWEB, GPEN, OSCP, CSSLP, CASE, or similar preferred
The priority is not tool-specific expertise but strong security fundamentals combined with hands-on execution: Application Security (SAST, DAST, SCA, secrets management) Threat Modelling Penetration Testing DevSecOps and Cloud Security Ability to leverage AI/LLMs and automation in security processes Strong coding and integration capabilities to build or automate workflows Strong Emphasis on Automation and AI Highlighted that the primary need is for engineers who can: Evaluate and implement security automation solutions. Use AI tools and agents to improve: Threat modelling SAST analysis Penetration testing Security workflow automation
Skills
Threat Modeling, SAST, DevSecOps, Cloud Security, Application Security, AWS Security, Workflow Automation, DAST, DevSecOps, Vulnerability Assessment and Penetration Testing, AI Security
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.