Performing application "Security Assessments" using automated and manual tools and recomend remediation controls.
Perform pentest and ethical hacking.
Participating in secure code review.
Partipicating/ Develope secure code with team to fix security issues.
Threat modeling to identify, quantify and address security risks related with apps and systems.
Educate software developing teams on secure coding practices and models/patterns/methodologies
Preparing and sharing educational materials, best practices and handbooks associated with app sec.
Specifying security requirements for Web and mobile apps.
Expertising on Microsoft Secure SDL/SDLC and OWASP SAMM models/methodology