Primary Function - AppSec & Supply Chain (PWS 1.16.4.4, 1.16.4.5): Implements the software assurance program, including static code analysis, DISA APP DEV STIG compliance, OWASP Top 10 mitigation, and SBOM (Software Bill of Materials) management. Maintains the Hardware Baseline Inventory to ensure no vulnerabilities are introduced through software or hardware supply chains.
Cross-Functional DevSecOps Integration (PWS 1.16.7.3):* Cross-trained in Software Development security practices to embed directly with the Development team during sprint cycles. Enables real-time code reviews, security assessments of application authorization controls, and immediate identification of vulnerabilities within development, staging, and production environments. Allows security validation to occur concurrently with development, catching OWASP Top 10 violations, unauthorized FOSS components, and access control misconfigurations before they reach production.