Application Security Training Lead (can send a really good application security engineer) NOT ANALYST
Hybrid : Reston VA
Fannie Mae
Key Responsibilities
Training Development & Delivery
- Design and deliver engaging training programs on secure coding practices OWASP Top 10 API security cloud-native security and advanced AppSec topics.
- Develop tailored training curricula for different audiences (engineers QA DevOps architects) that align with organizational risk posture.
- Facilitate hands-on labs workshops and capture-the-flag (CTF) exercises to ensure practical application of secure coding concepts.
- Maintain a blended learning model (instructor-led e-learning and self-service) to scale AppSec training across the enterprise.
Advisory & Coaching
- Partner with engineering leadership to identify training needs and knowledge gaps across teams.
- Provide one-on-one coaching and office hours to developers working on remediation of vulnerabilities in real-world codebases.
- Serve as a subject-matter expert for application security issues guiding engineers on best practices in Java Python JavaScript and cloud-native ecosystems.
Program Management & Metrics
- Develop and maintain a training roadmap aligned with compliance frameworks (e.g. ISO 27001 NIST PCI-DSS).
- Track and report training effectiveness through assessments developer feedback and vulnerability reduction metrics.
Collaborate with AppSec and DevSecOps teams to align training objectives with
SDLC security maturity goals.