Job Summary
ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.
Key Responsibilities
ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.
Skill Requirements
ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.
Other Requirements
ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.