XPT Software Australia Pty Ltd
DevSecOps Specialist
Posted Sep 22, 2026
Role Purpose
Own the technical design, standards, and hands-on delivery of SAST/SCA capability across GitLab SaaS and GitLab On-Prem. This role carries the full depth of an AppSec Specialist's skillset — secure SDLC design, vulnerability management discipline, architecture review, developer enablement — but applied narrowly and intensively to this one initiative for its duration, rather than as an ongoing cross-portfolio function.
Key Responsibilities
- Assess current SDLC and CI/CD pipeline architecture across both GitLab SaaS and Self-Managed/On-Prem instances, including version currency on the On-Prem side.
- Stakeholder management as there are different owners for Gitlab SaaS and Gitlab OnPrem
- Define the target-state SAST/SCA architecture: which GitLab-native features to use (Advanced SAST, dependency scanning, container/secrets scanning if in scope), where coverage gaps exist, and whether a third-party tool is required to close them.
- Review pipeline and repo structure for security-relevant design issues (authN/authZ patterns, trust boundaries, dependency exposure) uncovered during rollout.
- Set scanning policy for the initiative: severity thresholds, blocking vs. non-blocking pipeline gates, exception/waiver criteria, and false-positive management approach.
- Define secure coding standards and guardrails scanning results should be measured against (e.g., OWASP ASVS, CWE Top 25), scoped to the languages/frameworks in this rollout.
- Design the vulnerability triage and remediation workflow, including SLAs by severity, and how findings map into existing ticketing/GRC tooling.
- Validate feasibility of BA-authored requirements before they're finalized; provide technical input into vendor evaluation/RFP if a third-party tool is shortlisted.
- Perform root-cause analysis on recurring finding patterns surfaced during pilot rollout, and adjust scanning configuration/rules accordingly.
- Provide technical sign-off on rollout readiness per team/project before scanning gates go live.
- Run secure coding and remediation training for engineering teams as scanning gates go live for their projects.
- Build lightweight internal documentation/reference material so teams can self-serve common remediation patterns after the SME's engagement ends.
- Document architecture decisions, policy rationale, and configuration standards in a form the client's ongoing security team can operate and extend after the fixed-term engagement concludes.
Experience Level
Senior, 8–12+ years in application security / secure software engineering, with at least 4–5 years hands-on with SAST/SCA tooling specifically, and prior experience in AppSec practice broadly enough to bring architecture review and developer-enablement skills, not just scanner configuration.
Required Knowledge & Skills
- Deep working knowledge of SAST, SCA, DAST, and secrets detection — internals of how static analyzers work, not just tool operation.
- Hands-on experience with GitLab's native security scanning (Advanced SAST, dependency scanning) across both SaaS and Self-Managed, including feature parity gaps between tiers/versions.
- Practical experience with at least one major third-party SAST/SCA tool to inform build-vs-buy decisions credibly.
- CI/CD pipeline engineering fluency — able to write/review .gitlab-ci.yml and reason about pipeline performance impact.
- Strong grasp of vulnerability scoring/prioritization (CVSS, EPSS, CWE) and experience avoiding alert fatigue in high-volume scanning environments.
- Secure design fundamentals — authN/authZ, threat modeling (e.g., STRIDE) — sufficient to review architecture surfaced during rollout.
- Strong communication skills for developer training and cross-team escalation handling.
- Telco or critical-infrastructure security experience is a strong plus given regulatory and change-control constraints.
Nice to Have
- Relevant certifications: OSCP, GWAPT, CSSLP, or equivalent.
- Experience running a phased SAST/SCA rollout across a large multi-team, multi-repo GitLab estate (100+ projects).
- Experience structuring handover documentation/runbooks for fixed-term security engagements.
Role snapshot
Job type
Full-time
Required skills
Similar jobs
Solution Designer
XPT Software Australia Pty Ltd
Senior Application Security Engineer
XPT Software Australia Pty Ltd
Business Analyst_Secure Coding & Application Security
XPT Software Australia Pty Ltd
Desktop Standard Workplace Services Grade 2 Engineer
XPT Software Australia Pty Ltd
Data Modeller
XPT Software Australia Pty Ltd
Data Architect- MS Fabric
XPT Software Australia Pty Ltd