Application Security Advisor/Trainer
Quick Overview
Job Description
Description:
Business Initiative/Purpose: (Goal, Business Impact, Accomplishments from the work)
- Support application teams in adopting modern application security scanning and remediation practices. This role helps developers understand and act on security findings and delivers hands-on enablement and training to accelerate remediation and reduce risk across the software development lifecycle.
Bachelor Degree: (Required, Preferred or Not Required)
- Preferred (equivalent coursework, internships, certifications, or hands-on experience considered in lieu of a degree).
Role Responsibilities: (what they will be doing)
- Advise and support application development teams on interpreting and remediating application security findings (static analysis / SAST, software composition analysis / SCA, secrets, API, container, and infrastructure-as-code scanning).
- Deliver enablement and training (working sessions, office hours, guides) that help developers understand common vulnerability patterns (CWEs) and the steps to fix them.
- Create and maintain self-service documentation, remediation playbooks, and training material.
- Partner with security and DevOps teams to support pipeline security integration and vulnerability burndown.
- Track remediation progress and help teams prioritize work by risk.
Must Have Skills/Prior Experiences: (Vendor should not submit any candidate that does not have these skills/prior experience.)
- Foundational hands-on programming/coding experience (e.g., Java, Python, JavaScript, C#, or similar).
- Understanding of core application security concepts (OWASP Top 10, secure coding, common vulnerability classes / CWEs).
- Familiarity with application security scanning concepts (static analysis, software composition analysis, secrets scanning).
- Ability to explain technical security concepts clearly to developers (strong written and verbal communication).
- Experience creating documentation or delivering training / enablement content.
PlNice to Have Skills/Prior Experiences: (Hiring Manager DOES NOT require these skills/ prior experience. However candidates with any of these will be looked at first.)
- Exposure to CI/CD pipeline security integration.
- Familiarity with container and cloud security scanning concepts.
- Experience with vulnerability management workflows and ticketing.
- Relevant coursework, internships, certifications, or personal projects in application or security engineering.
EEO
“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”
Similar jobs
Application Security Advisor / Trainer
Apex Systems · Atlanta, United States
1 hour agoEHR Training Specialist
Mansai Corporation · Baltimore, United States
6 hours agoEHR Training Specialist
Jupiter IT Solutions LLC · Baltimore, United States
8 hours agoIT Communication & Training Specialist
Robert Half · Saint Charles, United States
21 hours agoTrainer
nFolks Data Solutions · Atlanta, United States
YesterdayProduct Trainer/Tech Writer - Level 2 or 3 with Security Clearance
Northrop Grumman · Boulder, United States
Yesterday$85.6k - $128.4k/yr