Back to all jobs

App Sac Specialist

Wipro

Princeton Junction, USA-NJ, USA on site full time

About this role

Job Description Title: SAST Checkmarx Specialist Location: Princeton NJ Duration: Full Time Role Summary Job Title: Application Security - On-site Role Summary Lead the execution and optimization of enterprise Application Security testing services, including SAST, SCA, Secrets Detection, and DAST. Drive secure SDLC adoption through CI/CD integration, vulnerability validation, infrastructure vulnerability management, risk-based remediation tracking, SBOM management, and security metrics reporting. Checkmarx tool experience is Mandatory Key Responsibilities Perform continuous and incremental application security testing using SAST, SCA, Secrets Detection, and DAST tools. Proficient in Checkmarx – architect level (Mandatory) Validate findings, eliminate false positives, and support vulnerability remediation activities. Integrate security scanning into CI/CD pipelines and enforce secure development gates. Manage SBOM generation, open-source dependency risks, CVE tracking, and vulnerability exposure reporting. Track remediation SLAs, TTD/TTR metrics, and application security KPIs. Partner with development, DevSecOps, and platform engineering teams to drive remediation and continuous security improvements. Support security assessments, tool optimization, reporting, and developer enablement initiatives. Review the report before publishing and lead the report readout meetings with the stakeholders Provide guidance and Technical governance to the team members Experience 10+ years of experience in Application Security, Secure SDLC, or DevSecOps. Hands-on experience operating enterprise App Sec scanning platforms and vulnerability management processes. Experience integrating security testing into CI/CD pipelines and cloud-native environments. Strong understanding of OWASP Top 10, secure coding practices, and software supply chain security. Technical Skills & Tool Experience SAST: Checkmarx. SCA & SBOM: Checkmarx DAST & API Security: Checkmarx Secrets Detection: Git Guardian/ GitHub Secret Scanning. DevSecOps: Azure DevOps/ GitHub Actions/ Jenkins/ GitLab CI/CD. Container & Cloud Security: Prisma Cloud/ Wiz/ Aqua/ Microsoft Defender for Cloud. Reporting & ITSM: ServiceNow/ PowerBI/ Grafana Preferred Certifications CEH/Security+/Certified DevSecOps Professional/AWS/Azure Security Specialty Areas of responsibility Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards. Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements. Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks. Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance." Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.

Apply for this position

Create an account to apply

Applying takes a free Yeap ID account — it's how you'll check your application status afterward, with no separate password to remember.