Technology Lead - Business Analyst
$400 - $470 AUD hourly
Beeline Request ID |
123594-1 |
Job Details:
|
Must Have Skills: GitLab SAST & SCA |
|
Nice to Have Skills: • Prior exposure to GitLab Self-Managed vs. SaaS migration or dual-topology environments. • Business analysis or security certifications (CBAP, Security+, or equivalent) — not mandatory but a positive signal. |
|
Detailed Job Description: Role Purpose Act as the bridge between the cybersecurity team, engineering/DevOps teams, and the SME/AI Expert on this initiative, translating the business need (“introduce SAST and SCA across GitLab SaaS and GitLab On-Prem”) into a structured requirements, rollout, and governance framework. This requires enough working knowledge of AppSec scanning concepts and GitLab's CI/CD model to write requirements an engineer or vendor can act on without a long clarification loop. Key Responsibilities • Run discovery across engineering, platform, and security stakeholders to map current-state SDLC, GitLab topology (SaaS groups/projects vs. Self-Managed instances), CI/CD pipeline patterns, and existing scanning tools (if any) across the telco's project portfolio. • Document functional and non-functional requirements for SAST and SCA (dependency scanning) coverage — language/framework coverage, false-positive tolerance, scan performance/pipeline latency impact, and whether secrets/container scanning are in scope. • Produce a build-vs-buy / tool-selection matrix comparing GitLab-native SAST/SCA (Free/Premium/Ultimate tiering) against third-party SAST/SCA tools, and identify where GitLab On-Prem version constraints affect feature availability versus SaaS. • Define the vulnerability management workflow: finding → triage → issue → remediation MR → SLA tracking, and how this maps into GitLab's vulnerability management dashboard versus existing ITSM/ticketing tools. • Write user stories/acceptance criteria for pipeline integration, exception/waiver processes, developer notification flows, and reporting/dashboards for CISO-level visibility. • Own the RAID log, stakeholder RACI, and rollout sequencing plan (pilot teams → phased fleet-wide rollout across SaaS and On-Prem estates). • Support change management: developer communication, training material coordination, and adoption metrics (scan coverage %, MTTR on findings, false-positive rate trend). • Liaise directly with the SME and AI Expert roles to ensure requirements reflect real tool capability and constraints rather than assumptions. Experience Level Mid-to-Senior, 6–10 years total BA experience, with at least 2–3 years specifically in cybersecurity, DevSecOps, or platform engineering programmes. Telco or large regulated-enterprise experience is a strong plus given data governance and change-control overhead. Required Knowledge & Skills • Working understanding of SAST vs. SCA vs. DAST vs. secrets detection — what each catches and doesn't. • Familiarity with GitLab CI/CD concepts (pipelines, merge requests, .gitlab-ci.yml) — doesn't need to write pipeline code, but must read and reason about one. • Understanding of GitLab licensing tiers (Free/Premium/Ultimate) and how SAST/SCA feature availability differs across them. • Vulnerability management lifecycle and common frameworks (CVSS scoring, CWE, OWASP Top 10) at working-fluency level, not expert depth. • Experience writing requirements/user stories for tooling or platform rollouts (not just business-process BA work). • Strong stakeholder facilitation skills — this programme spans security, engineering, and platform teams who often have competing priorities. • Comfortable working with technical SMEs to validate feasibility rather than dictating requirements in isolation. |
Minimum Years of Experience: 6+ yrs |
Certifications Needed: N/A |
|
Top 3 responsibilities you would expect the Subcon to shoulder and execute
|
Interview Process (Is face to face required?): No |
Any additional information you would like to share about the project specs/ nature of work: N/A |