5+ years of experience in application security.
Strong understanding of software development principles and practices.
In-depth knowledge of OWASP top 10 and common issues with insecure coding practices
Experience with secure coding practices, code reviews (SAST / DAST / MAST), and penetration testing.
Familiarity with industry standards and frameworks (OWASP, NIST, etc.).
Excellent communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.
Certifications such as GXPN, CISSP, CEH, or CSSLP are a plus.
Professional Development experience in enterprise class frameworks and programming languages