Talent.com
Zoho
Business Analyst with SAST/SCAZoho • Sydney, NSW, AU
Search for other jobs
Business Analyst with SAST/SCA

Business Analyst with SAST/SCA

Zoho • Sydney, NSW, AU
2 days ago
Job description

Job Description

XPT Software Australia Pty Ltd | Contract

Business Analyst with SAST/SCA \n

Sydney, Australia | Posted on 09/29/2026

\n

    \n
  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • \n
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • \n
  • We have 120+technocrats in Australia working at our clientlocations.
  • \n
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • \n
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
  • \n

Job Description \n

Position: Business Analyst with SAST/SCA

\n

Role Purpose:

\n

Act as the bridge between the cybersecurity team, engineering/DevOps teams, and the SME/AI Expert on this initiative, translating the business need (“introduce SAST and SCA across GitLab SaaS and GitLab On-Prem”) into a structured requirements, rollout, and governance framework. This requires enough working knowledge of AppSec scanning concepts and GitLab's CI/CD model to write requirements an engineer or vendor can act on without a long clarification loop

\n

Key Responsibilities

\n

    \n
  • Run discovery across engineering, platform, and security stakeholders to map current-state SDLC, GitLab topology (SaaS groups/projects vs. Self-Managed instances), CI/CD pipeline patterns, and existing scanning tools (if any) across the telco's project portfolio.
  • \n
  • Document functional and non-functional requirements for SAST and SCA (dependency scanning) coverage — language/framework coverage, false‑positive tolerance, scan performance/pipeline latency impact, and whether secrets/container scanning are in scope.
  • \n
  • Produce a build‑vs‑buy / tool‑selection matrix comparing GitLab-native SAST/SCA (Free/Premium/Ultimate tiering) against third‑party SAST/SCA tools, and identify where GitLab On‑Prem version constraints affect feature availability versus SaaS.
  • \n
  • Define the vulnerability management workflow: finding → triage → issue → remediation MR → SLA tracking, and how this maps into GitLab's vulnerability management dashboard versus existing ITSM/ticketing tools.
  • \n
  • Write user stories/acceptance criteria for pipeline integration, exception/waiver processes, developer notification flows, and reporting/dashboards for CISO‑level visibility.
  • \n
  • Own the RAID log, stakeholder RACI, and rollout sequencing plan (pilot teams → phased fleet‑wide rollout across SaaS and On‑Prem estates).
  • \n
  • Support change management: developer communication, training material coordination, and adoption metrics (scan coverage %, MTTR on findings, false‑positive rate trend).
  • \n
  • Liaise directly with the SME and AI Expert roles to ensure requirements reflect real tool capability and constraints rather than assumptions.
  • \n

\n

Experience Level

\n

Mid-to-Senior, 6–10 years total BA experience, with at least 2–3 years specifically in cybersecurity, DevSecOps, or platform engineering programmes. Telco or large regulated‑enterprise experience is a strong plus given data governance and change‑control overhead

\n

Required Knowledge & Skills

\n

    \n
  • Working understanding of SAST vs. SCA vs. DAST vs. secrets detection — what each catches and doesn't.
  • \n
  • Familiarity with GitLab CI/CD concepts (pipelines, merge requests, .gitlab-ci.yml) — doesn't need to write pipeline code, but must read and reason about one.
  • \n
  • Understanding of GitLab licensing tiers (Free/Premium/Ultimate) and how SAST/SCA feature availability differs across them.
  • \n
  • Vulnerability management lifecycle and common frameworks (CVSS scoring, CWE, OWASP Top 10) at working‑fluency level, not expert depth.
  • \n
  • Experience writing requirements/user stories for tooling or platform rollouts (not just business‑process BA work).
  • \n
  • Strong stakeholder facilitation skills — this programme spans security, engineering, and platform teams who often have competing priorities.
  • \n
  • Comfortable working with technical SMEs to validate feasibility rather than dictating requirements in isolation.
  • \n

\n

Nice to Have

\n

    \n
  • Prior exposure to GitLab Self-Managed vs. SaaS migration or dual‑topology environments.
  • \n
  • Business analysis or security certifications (CBAP, Security+, or equivalent) — not mandatory but a positive signal
  • \n

#J-18808-Ljbffr

Create a job alert for this search

Business Analyst with SAST/SCA • Sydney, NSW, AU