Salary
💰 $175,000 - $200,000 per year
Tech Stack
AWSAzureCloudGoJavaJavaScriptMicroservicesPythonSaltStackTypeScript
About the role
- Serve as DevSecOps Application Security presales solutions expert supporting Trace3 sales teams
- Lead presales engagements as the DevSecOps Application Security subject matter expert to Trace3 customers and sales teams nationally
- Work closely with sales teams throughout the sales process to ensure client technical needs are understood and met
- Drive technical relationships with stakeholders and support sales opportunities
- Present at client-facing and industry events as the SME in application security
- Conduct research analysis and lab testing of application security solutions to evaluate efficacy and fit-for-purpose
- Build and maintain application security vendor partner relationships
- Develop customer-facing and internal presales collateral and service offering documentation
- Plan and lead implementation and adoption of application security platforms
- Review customer software architecture and source code and provide developer training
- Champion Agile and DevOps leading-practices, design patterns, and tools in support of DevSecOps transformation
- Assist in services opportunity generation, technical scoping, and Statements of Work (SOW) writing
- Assist in delivery of application security services and drive adoption across development teams
Requirements
- At least 5 years of Development Experience in any programming language
- Minimum of 5 years of combined hands-on experience as a software engineer, DevOps engineer, or Application Security engineer
- Previous experience working as a Sales Engineer or Solutions Architect working with application security software products or services
- Strong understanding of cloud-native development patterns, microservices architecture, and the deployment and security of applications in cloud-native environments
- Ability to assess customer requirements, identify business problems, and demonstrate proposed solutions
- Programming and scripting proficiency – minimum of two: C#, Java, Typescript, Javascript, Bash, Python, Go
- Hands on experience with various application security tools including SAST, SCA, IAST, DAST, API Security, WAF, and RASP
- Hands on experience implementing and integrating security tools into CI/CD
- Hands on experience integrating and operating commercial application security solutions (Veracode, Fortify, Checkmarx, Synopsys, WhiteSource, Snyk, Invicti, Contrast Security)
- Experience delivering secure software based on frameworks such as OWASP SAMM, ASVS, MASVS, CWE, SANS, BSIMM
- Experience with Agile methodologies such as Scrum and Kanban
- Knowledge of developer tools and environments, project management and bug tracking systems
- Prior experience working at an application security vendor – bonus points
- Experience with API security solutions such as Traceable, Noname Security, Salt Security
- Understanding of service-oriented architecture (REST APIs, micro-services, etc) and security best practices
- DevOps and Architecture experience and certifications with one of the major public cloud providers (AWS, Azure, Google Cloud)
- Experience with conducting secure coding training, implementing security champions program, threat modeling, or application security testing
- Prior consulting experience is a plus
- Must have excellent interpersonal skills, a high degree of professionalism and the ability to design technology solutions for commercial and large enterprise companies
- Excellent presentation, communication, and writing skills required