At ista, we empower property owners and managers to operate their buildings in a future-proof, energy-efficient, and digital way. To achieve this, we develop and run a wide range of business-critical applications and digital platforms.
In this role, you will actively drive the advancement of our application security landscape and work closely with international development and platform teams to ensure that security is embedded from the very beginning in applications, products, and architectural decisions. Together with our development teams, you will foster a culture where secure software development becomes the norm and security is recognized as a shared success factor.
- Drive the evolution of our Application Security strategy and embed Security-by-Design and Security-by-Default principles across international software development teams
- Advise Product Owners, Developers, Architects, and Platform Teams on the secure development and operation of applications
- Define and establish standards, frameworks, and secure coding guidelines based on industry best practices such as OWASP, Microsoft SDL, NIST SSDF, and ISO 27034
- Conduct security reviews, threat modeling sessions, and architecture assessments to identify and evaluate application security risks
- Integrate security requirements and tools such as SAST, DAST, SCA, Secret Scanning, and Container Security into modern development and CI/CD processes
- Collaborate closely with Development Squads, Platform Engineering, Architecture, and Pentesting Teams to remediate vulnerabilities and implement security requirements sustainably
- Build and enhance an international Secure Development Community through training programs, Security Champion initiatives, and continuous knowledge sharing
- Monitor emerging threats, vulnerabilities, and trends in Application Security and assess their relevance for ista