العودة إلى الوظائف
ScovaiScovaiJobs
XPT Software Australia Pty Ltd

XPT Software Australia Pty Ltd

Business Analyst with SAST/SCA

Sydney, AUفي الموقعدائمدوام كامل

تم النشر في 29 سبتمبر 2026

تم نشر هذه الوظيفة باللغة EN

Position: Business Analyst with SAST/SCA

Role Purpose:

Act as the bridge between the cybersecurity team, engineering/DevOps teams, and the SME/AI Expert on this initiative, translating the business need (“introduce SAST and SCA across GitLab SaaS and GitLab On-Prem”) into a structured requirements, rollout, and governance framework. This requires enough working knowledge of AppSec scanning concepts and GitLab's CI/CD model to write requirements an engineer or vendor can act on without a long clarification loop

Key Responsibilities

  • Run discovery across engineering, platform, and security stakeholders to map current-state SDLC, GitLab topology (SaaS groups/projects vs. Self-Managed instances), CI/CD pipeline patterns, and existing scanning tools (if any) across the telco's project portfolio.
  • Document functional and non-functional requirements for SAST and SCA (dependency scanning) coverage — language/framework coverage, false-positive tolerance, scan performance/pipeline latency impact, and whether secrets/container scanning are in scope.
  • Produce a build-vs-buy / tool-selection matrix comparing GitLab-native SAST/SCA (Free/Premium/Ultimate tiering) against third-party SAST/SCA tools, and identify where GitLab On-Prem version constraints affect feature availability versus SaaS.
  • Define the vulnerability management workflow: finding → triage → issue → remediation MR → SLA tracking, and how this maps into GitLab's vulnerability management dashboard versus existing ITSM/ticketing tools.
  • Write user stories/acceptance criteria for pipeline integration, exception/waiver processes, developer notification flows, and reporting/dashboards for CISO-level visibility.
  • Own the RAID log, stakeholder RACI, and rollout sequencing plan (pilot teams → phased fleet-wide rollout across SaaS and On-Prem estates).
  • Support change management: developer communication, training material coordination, and adoption metrics (scan coverage %, MTTR on findings, false-positive rate trend).
  • Liaise directly with the SME and AI Expert roles to ensure requirements reflect real tool capability and constraints rather than assumptions.

Experience Level

Mid-to-Senior, 6–10 years total BA experience, with at least 2–3 years specifically in cybersecurity, DevSecOps, or platform engineering programmes. Telco or large regulated-enterprise experience is a strong plus given data governance and change-control overhead

Required Knowledge & Skills

  • Working understanding of SAST vs. SCA vs. DAST vs. secrets detection — what each catches and doesn't.
  • Familiarity with GitLab CI/CD concepts (pipelines, merge requests, .gitlab-ci.yml) — doesn't need to write pipeline code, but must read and reason about one.
  • Understanding of GitLab licensing tiers (Free/Premium/Ultimate) and how SAST/SCA feature availability differs across them.
  • Vulnerability management lifecycle and common frameworks (CVSS scoring, CWE, OWASP Top 10) at working-fluency level, not expert depth.
  • Experience writing requirements/user stories for tooling or platform rollouts (not just business-process BA work).
  • Strong stakeholder facilitation skills — this programme spans security, engineering, and platform teams who often have competing priorities.
  • Comfortable working with technical SMEs to validate feasibility rather than dictating requirements in isolation.

Nice to Have

  • Prior exposure to GitLab Self-Managed vs. SaaS migration or dual-topology environments.

Business analysis or security certifications (CBAP, Security+, or equivalent) — not mandatory but a positive signal

ملخص الدور

نوع الوظيفة

دوام كامل

المهارات المطلوبة

SAST/SCA/DAST/Secrets detection knowledgeGitLab CI/CD concepts (pipelines, merge requests, .gitlab-ci.yml)GitLab licensing tier knowledge (Free/Premium/Ultimate)Vulnerability management lifecycle and frameworks (CVSS, CWE, OWASP Top 10)Writing requirements and user stories with acceptance criteria for tooling/platform rolloutsStakeholder facilitation and management across security, engineering, and platform teamsTechnical SME collaboration and feasibility validationCurrent-state discovery and process mapping of SDLC and GitLab topologyTool evaluation and build-vs-buy/vendor selection analysis for SAST/SCAVulnerability management workflow design and integration with ITSM/ticketing (triage→issue→remediation→SLA)RAID log, stakeholder RACI creation, and rollout sequencing/project planningChange management, developer communication, training coordination, and adoption metrics (scan coverage%, MTTR, false-positive trends)

وظائف مشابهة

XPT Software Australia Pty Ltd

Azure Cloud Solution Architect with Kraken

XPT Software Australia Pty Ltd

Sydney, AUفي الموقعدائمدوام كامل
قبل 18 ساعة
XPT Software Australia Pty Ltd

Performance Test Engineer

XPT Software Australia Pty Ltd

Sydney, AUفي الموقعدائمدوام كامل
أمس
Deliverect

Implementation Consultant

Deliverect

Sydney, AUفي الموقعدائمدوام كامل
أول أمس
XPT Software Australia Pty Ltd

Automation Test Architect

XPT Software Australia Pty Ltd

Sydney, AUفي الموقعدائمدوام كامل
أول أمس
XPT Software Australia Pty Ltd

DevOps Engineer

XPT Software Australia Pty Ltd

Sydney, AUفي الموقعدائمدوام كامل
قبل 7 أيام
XPT Software Australia Pty Ltd

IBM FileNet Developer

XPT Software Australia Pty Ltd

Sydney, AUفي الموقعدائمدوام كامل
قبل 7 أيام
Business Analyst with SAST/SCA في XPT Software Australia Pty Ltd في Sydney | Scovai | Scovai