Responsibilities
- Direct the Application Security initiative across all Armis offerings, incorporating security practices into every phase of the software development lifecycle.
- Execute secure design and architecture assessments, collaborating with engineering groups to detect and address risks proactively.
- Facilitate and guide threat modeling exercises applying STRIDE, DREAD, or PASTA frameworks.
- Manage application-level vulnerability handling as a component of the VIPR approach, covering identification, resolution, and verification.
- Incorporate AppSec results from SAST, DAST, SCA, and API testing into unified vulnerability processes, risk evaluation, and prioritization systems.
- Link application weaknesses with asset details, exploit data, and business importance to inform remediation based on risk.
- Monitor and communicate VMDR indicators like mean time to detect, mean time to resolve, exposure periods, and remediation efficacy for application vulnerabilities.
- Create and sustain automated AppSec workflows for SAST, DAST, SCA, and API security assessments.
- Work with DevOps to embed security checks into continuous integration and deployment pipelines using tools such as GitHub Actions, Jenkins, and Buildkite.
- Cooperate with Cloud and Infrastructure Security teams to protect APIs, microservices, and containerized environments like Docker and Kubernetes.
- Establish and update secure coding guidelines and security benchmarks for technologies including React, Node.js, Python, Java, and Go.
- Guide engineers and security advocates; provide instruction on secure coding and threat modeling sessions.
- Serve as a reliable consultant to engineering management, converting vulnerabilities into understandable risk and corrective advice.
- Aid in compliance and audit preparations for standards such as SOC 2, ISO 27001, FedRAMP, and HIPAA, ensuring application risks are recorded and handled within VIPR and AppSec procedures.