Website Inventions Technologies Company Limited
Inventions Technologies Company Limited
SSDLC Specialist, Cybersecurity at Inventions Technologies Company Limited
Employer: Inventions Technologies Company Limited
Position: SSDLC Specialist, Cybersecurity
Employment Type: Full-Time
Department: Cybersecurity
Reports To: Manager, Cyber Strategy and Secure by Design
Job Category: Cybersecurity / Software Engineering / Information Technology
Location: Tanzania
Job Purpose
The SSDLC Specialist is a member of the Cybersecurity Department, reporting to the Manager, Cyber Strategy and Secure by Design.
The role defines, governs and improves the Secure Software Development Life Cycle (SSDLC) while applying architecture, solution design and hands-on development expertise to ensure applications and digital services are secure by design, scalable, resilient and maintainable.
Key Responsibilities
1. SSDLC Governance and Assurance
- Define and maintain SSDLC policies, standards, templates, security controls, quality gates and evidence requirements.
- Embed secure-by-design practices across Agile, DevOps and DevSecOps delivery, from requirements through retirement.
- Perform lifecycle assurance, identify security exceptions, vulnerabilities and technical debt, and oversee remediation.
- Maintain traceability and metrics covering security requirements, design decisions, testing, releases, defects and incidents.
2. Architecture and Solution Design
- Translate business, functional, security and non-functional requirements into secure solution architectures and detailed technical designs.
- Design scalable and resilient applications, APIs, integrations, data models, cloud components, security controls and observability capabilities.
- Evaluate technologies and patterns; produce architecture diagrams, specifications and decision records.
- Conduct threat modelling, architecture and design reviews, proofs of concept and technical risk assessments.
3. Secure Software Engineering
- Develop, integrate and refactor production-quality software, prototypes, reference implementations and reusable components.
- Apply secure coding, version control, peer review, automated testing and software supply-chain controls.
- Review code, troubleshoot complex defects and vulnerabilities, and guide root-cause analysis and remediation.
- Improve CI/CD pipelines, security scanning, release controls, performance, production readiness and rollback capability.
4. Technical Leadership and Collaboration
- Partner with product, architecture, engineering, testing, operations, cybersecurity and supplier teams.
- Coach delivery teams on architecture, design, secure coding, testing and SSDLC requirements.
- Support technical planning, supplier evaluation, solution acceptance and communities of practice.
Qualifications and Experience
- Bachelor’s degree in Computer Science, Software Engineering, Information Technology, or a related discipline.
- At least two (2) years of software engineering experience covering architecture, detailed design and hands-on development.
- Experience delivering secure systems through Agile, DevOps and DevSecOps practices.
- Practical experience with APIs, integrations, data models, cloud platforms, source control, automated testing, CI/CD, containers and observability.
- Relevant certification in architecture, cloud, secure software development, Agile, DevOps or DevSecOps is advantageous.
Required Skills and Competencies
Architecture and Design
- Distributed and cloud-native systems.
- Microservices.
- APIs and integrations.
- Data modelling.
- Design patterns.
- Performance and resilience.
Development
- Strong proficiency in at least one enterprise programming language.
- Ability to review code across different technology stacks.
Secure Engineering
- Threat modelling.
- Secure coding.
- Identity and access management.
- API security.
- Secrets protection.
- Vulnerability management.
- Software supply-chain security.
Tooling and Operations
- Git.
- CI/CD.
- Automated testing and security scanning.
- Artefact management.
- Containers.
- Monitoring and tracing.
- Release management.
Core Competencies
- Systems thinking.
- Analytical problem-solving.
- Technical judgement.
- Clear communication.
- Collaboration.
- Coaching.
- Accountability.
- Strong attention to quality.
Key Performance Measures
- Compliance with SSDLC, cybersecurity and architecture quality gates.
- Reduction in escaped defects, repeat vulnerabilities, security-related incidents and overdue remediation actions.
- Timeliness and quality of architecture, design and code reviews.
- Improvement in automated testing, security scanning and deployment coverage.
- Adoption of approved secure patterns, reusable components and engineering standards.
How to Apply
To apply for the SSDLC Specialist, Cybersecurity position, submit your application through the employer’s application portal:
To apply for this job please visit ierp.it.co.tz.
