Application Security
Embedding secure-by-design into the SDLC.
Lead AppSec strategy across web, API, and cloud-native platforms. Identify and remediate vulnerabilities at the design stage and across the entire delivery pipeline.
- SAST, DAST and SCA tooling integration
- Secure code review across .NET, Java, Node.js
- Threat modeling using STRIDE
- Authentication, authorization and input validation review
- Vulnerability management lifecycle ownership
