Logo for NextLink Group

Application Security SME

Roles & Responsibilities

  • 8+ years of senior Application Security experience in a custom development environment
  • Strong experience with AppSec tooling (Snyk, Invicti, Sonatype, Intigriti or equivalents)
  • Experience with secure SDLC, secure coding concepts, and vulnerability management
  • Ability to guide a Center of Excellence (CoE) in large, multi-stakeholder organizations with expert-level guidance while not requiring daily hands-on work

Requirements:

  • Guide operations of the AppSec Center of Excellence (1–2 times per week), review dashboards, and handle escalations
  • Support application owners and developers with onboarding, tooling integration questions, and complex AppSec cases
  • Drive improvements in AppSec processes, metrics, and documentation
  • Lead or contribute to security tooling migrations (Invicti and Sonatype SaaS) and provide input on design security reviews, code reviews, and threat modeling when required

Job description

This is a remote position.

We are strengthening our Application Security function within custom development. The role sits under the Head of Application Security and focuses on securing internally developed applications, SaaS applications, and supporting cloud security initiatives.
The position supports and guides a Center of Excellence (CoE) based in India that performs day-to-day operational AppSec activities. The mission also includes leading two major tooling evolutions: the migration of Invicti to its new platform and the migration of Sonatype from on premise to a SaaS solution.
The environment is complex and international, involving many stakeholders across development, data science, security, and platform teams.

Typical Day
• Regular touchpoints (1–2 times per week) with the AppSec Center of Excellence to guide operations, review dashboards, and handle escalations
• Supporting application owners and developers with onboarding, tooling integration questions, and complex AppSec cases
• Driving improvements in AppSec processes, metrics, and documentation
• Leading or contributing to security tooling migrations (Invicti and Sonatype SaaS)
• Collaborating with stakeholders to define roadmaps and improve secure development practices
• Providing expert input on design security reviews, code review reports, and threat modeling when required
 


Requirements

Years of Experience: Senior profile required – typically 8+ years of experience

Must Have
• Strong experience in Application Security within a custom development context
• Solid understanding of AppSec tooling (e.g. Snyk, Invicti, Sonatype, Intigriti or equivalent tools)
• Experience with secure SDLC, secure coding concepts, and vulnerability management
• Ability to work at expert level without being fully hands-on daily, guiding a CoE instead
• Experience working in large / complex organizations with multiple stakeholders
• Strong communication skills in English 
• Proactive and autonomous mindset

Ideal Candidate
• A senior Application Security professional who can take ownership of tooling and processes
• Comfortable acting as a subject matter expert and advisor, not just an operator
• Proactive in identifying gaps, proposing improvements, and driving initiatives forward
• Able to engage confidently with developers, architects, platform teams, and security leadership
• Capable of quickly mastering existing tools and new functionalities to maximize value

Nice to Have
• Prior experience with UCB’s specific tools (Snyk, Invicti, Sonatype, Intigriti)
• Security certifications (AppSec, testing, or security-related)
• Pharma / life sciences exposure
• Familiarity with GxP concepts (not mandatory, limited impact)
• Exposure to GenAI / LLM security topics
 


Related jobs

Other jobs at NextLink Group

We help you get seen. Not ignored.

We help you get seen faster — by the right people.

🚀

Auto-Apply

We apply for you — automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.