Чем предстоит заниматься
Vulnerability Management: Review source code and application architectures to identify and communicate security vulnerabilities to development teams
Supply Chain Security: Drive the adoption of Software Bill of Materials (SBOM) to provide visibility into the software supply chain and ensure license compliance and vulnerability tracking
3rd Party Risk Mitigation: Implement and manage automated Software Composition Analysis (SCA) to identify and remediate vulnerabilities in open-source and third-party libraries
CI/CD Pipeline Security: Develop and support automated security tooling and agentic security workflows within CI/CD pipelines to streamline vulnerability triage, third-party scanning, and threat modeling
Remediation Support: Work closely with the penetration testing team to identify and implement remediations for identified security vulnerabilities
Threat Response: Support the implementation of security configurations and countermeasures based on emerging threats and industry trends