Summary
β¨ AIβGenerated
A business analyst role focused on application security and DevSecOps initiatives. The position involves gathering requirements, supporting security implementations, and coordinating between engineering and security stakeholders.
Highlights
Opportunity to bridge business and technical teams while shaping security processes and modern software delivery practices.
Description
Role: Business Analyst β AppSec / DevSecOps / GitLab SAST & SCA
Experience: 6β10 years overall BA experience, with 2β3+ years in Cybersecurity, Application Security, DevSecOps, or Platform Engineering.
Role Purpose
We are looking for a Business Analyst with strong Application Security and DevSecOps knowledge to act as the bridge between Cybersecurity, Engineering/DevOps, Platform teams, and technical SMEs.
The role will translate business and security requirements into structured requirements, rollout plans, governance processes, and implementation frameworks for GitLab SAST and SCA across GitLab SaaS and Self-Managed/On-Prem environments.
Key Responsibilities
Conduct discovery sessions with Engineering, Platform, DevOps, and Security teams to understand the current SDLC, GitLab topology, CI/CD processes, and existing security scanning tools.Define functional and non-functional requirements for SAST and SCA/dependency scanning.Assess requirements around programming language/framework coverage, scan performance, pipeline impact, false positives, and security scanning scope.Develop build-vs-buy and tool-selection matrices comparing GitLab-native SAST/SCA with third-party security scanning solutions.Assess differences between GitLab SaaS and GitLab Self-Managed/On-Prem environments, including version and feature limitations.Define the vulnerability management lifecycle from finding β triage β issue β remediation β SLA tracking.Map GitLab vulnerability management processes with existing ITSM/ticketing platforms.Create user stories, functional requirements, acceptance criteria, and process documentation.Define requirements for pipeline integration, security exceptions/waivers, developer notifications, dashboards, and reporting.Support CISO-level reporting requirements, including scan coverage, vulnerability trends, MTTR, and false-positive rates.Maintain RAID logs, RACI matrices, stakeholder maps, and rollout plans.
Required Skills
Business AnalysisApplication Security / AppSecDevSecOpsGitLab SAST & SCAGitLab CI/CDGitLab SaaS and Self-ManagedVulnerability ManagementSAST, SCA, DAST, Secrets DetectionCVSS, CWE, OWASP Top 10