Information Security Specialist: Lead

Millennium Group

$120K — $145K *
US-AnywhereRemote in Texas, US
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in Application Security and/or Software Security.
  • Hands-on experience with Static Application Security Testing (SAST).
  • Proficient in integrating security controls within CI/CD pipelines.
  • Strong background in source code vulnerability remediation.
  • Familiar with GitLab and related platforms like Artifactory/JFrog.
  • Ability to work independently on security initiatives.
  • Excellent communication skills for effective collaboration.

Responsibilities

  • Review and validate SAST findings in the software development lifecycle.
  • Collaborate with developers to investigate vulnerabilities and prioritize fixes.
  • Configure and manage GitLab security workflows and policies.
  • Support AI-assisted triage and automated findings management.
  • Develop automation for managing security findings and reporting.
  • Onboard and operationalize new Application Security tools.
  • Enhance Secure SDLC processes by partnering with cross-functional teams.

Benefits

  • Possibility of remote work opportunities.
  • Access to professional development and training resources.
  • Collaborative work environment that encourages innovation.
  • Comprehensive health and wellness programs.
  • Flexible working hours for improved work-life balance.
Full Job Description
Information Security Specialist - Lead (Application Security)

Key Responsibilities
  • Review and validate Static Application Security Testing (SAST) findings generated during the software development lifecycle.
  • Partner with development teams to investigate vulnerabilities, reduce false positives, and prioritize remediation activities.
  • Configure and maintain GitLab security approval workflows, Secure Merge Request controls, approval policies, and enforcement gates.
  • Support implementation of AI-assisted triage, remediation recommendations, and automated findings management.
  • Build and maintain automation for finding enrichment, correlation, routing, deduplication, and reporting.
  • Support onboarding and operationalization of new Application Security tooling and capabilities.
  • Drive risk-based prioritization and improve developer adoption of secure coding practices.
  • Collaborate with engineering, security, and product teams to optimize Secure SDLC processes and workflows.
  • Assist with integration of security platforms and enterprise technology solutions.
  • Provide guidance regarding remediation strategies, exception processes, and security best practices.
Required Qualifications
  • 10+ years of Application Security and/or Software Security experience.
  • Hands-on experience performing SAST reviews.
  • Experience integrating security controls into CI/CD pipelines.
  • Strong experience with source code vulnerability remediation.
  • Experience with GitLab.
  • Experience with Artifactory and/or JFrog platforms.
  • Ability to work independently and drive security initiatives with minimal oversight.
  • Strong communication skills and the ability to collaborate effectively with development teams and stakeholders.
Preferred Qualifications
  • Experience with Dynamic Application Security Testing (DAST).
  • Experience with Software Composition Analysis (SCA).
  • Experience with Polaris.
  • Experience with OWASP ZAP.
  • Familiarity with AI-enabled security automation and remediation workflows.
  • Experience with Container Security and Secrets Detection tools.
  • Understanding of software supply chain security and modern DevSecOps practices.
  • Experience integrating security platforms with GitLab, ServiceNow, Jira, and enterprise reporting solutions.
  • Experience leveraging APIs, scripting, and automation to improve security operations.

Similar Jobs

More Jobs at Millennium Group

More Information Technology Jobs

Find similar Information Security Specialist: Lead jobs: