Senior Application Security Engineer

Michael Page · Sydney NSW 2000 · Full time
Posted 7d ago

Senior Application Security Engineer

Michael Page
Sydney NSW 2000

·

Full time

~$120k - $150k(Estimated)
Michael Page Logo
KEY POINTS WE FOUND
  • Lead the implementation and onboarding of Secure Code Scanning platforms across the software development lifecycle.
  • Collaborate with development, DevOps, and security teams to define scanning strategies and remediation workflows.
  • Establish vulnerability management processes and provide hands-on support during implementation.

  • Hybrid environment and flexible working

About Our Client

Our client is a leading global technology consulting and services organisation that partners with enterprises to deliver large-scale digital transformation, cloud, cybersecurity, and technology modernisation initiatives. They offer a collaborative and innovative environment, providing opportunities to work on complex enterprise programs leveraging modern technologies and best-practice delivery frameworks.

Job Description

Key responsibilities:

  • Lead the implementation and onboarding of Secure Code Scanning platforms such as Snyk, Fortify, Checkmarx, or Veracode across the software development lifecycle.
  • Design and implement integrations with GitHub, GitLab and CI/CD pipelines to enable automated security scanning and policy enforcement.
  • Collaborate with development, DevOps, and security teams to define scanning strategies, remediation workflows, quality gates, and secure coding controls.
  • Proactively identify implementation challenges, integration dependencies, developer adoption issues, and performance impacts, and provide practical solutions to mitigate risks.
  • Establish vulnerability management processes, including triage, risk prioritisation, exception handling, SLA definition, and remediation tracking.
  • Develop technical standards, deployment procedures, operational runbooks, and governance processes to support long-term platform adoption.
  • Provide hands-on support during implementation, testing, rollout, and post-go-live stabilization activities while mentoring development teams on secure coding practices.

The Successful Applicant

A successful Senior Application Security Engineer should have:

  • Proven experience as an Application Security Engineer or DevSecOps Engineer in enterprise environments.
  • Hands-on experience implementing SAST tools such as Snyk, Fortify, Checkmarx, or Veracode.
  • Strong knowledge of secure coding practices, application security, and SSDLC principles.
  • Experience integrating security tooling into GitHub, GitLab, and CI/CD pipelines.
  • Expertise in vulnerability management, remediation workflows, and risk prioritisation.
  • Strong stakeholder engagement skills with the ability to work across Security, Development, and DevOps teams.
  • Excellent problem-solving abilities and a practical, delivery-focused approach.
  • Experience driving adoption of security controls and DevSecOps practices across development teams.
  • Demonstrate experience implementating similar Application Security and Secure Coding solutions in larger enterprise environments
  • Excellent communication skills to collaborate with technical teams.

What's on Offer

  • Transformation project
  • Hybrid environment and flexible working
  • Long-term opportunity with project
  • Ability to upskill and work with security and AI

If this role aligns with your skills and experience, we encourage you to apply.

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 20 matched
Application securityCheckmarxCi/cd pipelinesCloud securityCollaborativeDevsecopsFortifyGithubGitlabProblem solvingSastSecure code scanningSecure codingSecure coding practicesSecurity controls adoptionSnykSsdlcStakeholder engagementVeracodeVulnerability management

Licenses & certifications

0 of 4 matched
Certified information systems security professional (cissp)Certified secure software lifecycle professional (csslp)Giac secure software programmer (gssp)None

Perks & benefits

0 of 3 matched
Flexible working hoursLong-term project involvementOpportunity to upskill

PageGroup

PageGroup Logo