Business Analyst - Application Security DevSecOps

Ampstek β€” Australia Β· Posted ~3 hours ago

Senior Full-time Visa History βœ“

Skills

business analysis application security DevSecOps GitLab SAST SCA CI/CD

πŸ”“ Log in to save this job, tailor your resume & track your apply process β€” 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A business analyst role focused on application security and DevSecOps initiatives. The position involves gathering requirements, supporting security implementations, and coordinating between engineering and security stakeholders.

Highlights

Opportunity to bridge business and technical teams while shaping security processes and modern software delivery practices.

Description

Role: Business Analyst – AppSec / DevSecOps / GitLab SAST & SCA Experience: 6–10 years overall BA experience, with 2–3+ years in Cybersecurity, Application Security, DevSecOps, or Platform Engineering. Role Purpose We are looking for a Business Analyst with strong Application Security and DevSecOps knowledge to act as the bridge between Cybersecurity, Engineering/DevOps, Platform teams, and technical SMEs. The role will translate business and security requirements into structured requirements, rollout plans, governance processes, and implementation frameworks for GitLab SAST and SCA across GitLab SaaS and Self-Managed/On-Prem environments. Key Responsibilities Conduct discovery sessions with Engineering, Platform, DevOps, and Security teams to understand the current SDLC, GitLab topology, CI/CD processes, and existing security scanning tools.Define functional and non-functional requirements for SAST and SCA/dependency scanning.Assess requirements around programming language/framework coverage, scan performance, pipeline impact, false positives, and security scanning scope.Develop build-vs-buy and tool-selection matrices comparing GitLab-native SAST/SCA with third-party security scanning solutions.Assess differences between GitLab SaaS and GitLab Self-Managed/On-Prem environments, including version and feature limitations.Define the vulnerability management lifecycle from finding β†’ triage β†’ issue β†’ remediation β†’ SLA tracking.Map GitLab vulnerability management processes with existing ITSM/ticketing platforms.Create user stories, functional requirements, acceptance criteria, and process documentation.Define requirements for pipeline integration, security exceptions/waivers, developer notifications, dashboards, and reporting.Support CISO-level reporting requirements, including scan coverage, vulnerability trends, MTTR, and false-positive rates.Maintain RAID logs, RACI matrices, stakeholder maps, and rollout plans. Required Skills Business AnalysisApplication Security / AppSecDevSecOpsGitLab SAST & SCAGitLab CI/CDGitLab SaaS and Self-ManagedVulnerability ManagementSAST, SCA, DAST, Secrets DetectionCVSS, CWE, OWASP Top 10