Application Security Consultant

  • Location: WOLUWE
  • Type: Contracting
  • Job #25804

Application Security Consultant

Job Summary:
We are seeking a highly skilled Application Security Consultant to enhance the security posture of applications across the software development lifecycle. The ideal candidate will have expertise in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and other security assessment methodologies. This role involves working closely with development, DevOps, and security teams to integrate security best practices, identify vulnerabilities, and recommend effective remediation strategies.

Key Responsibilities:

  • Conduct SAST and DAST assessments to identify security vulnerabilities in applications.
  • Perform security code reviews and manual testing to uncover security flaws.
  • Implement and integrate security tools into CI/CD pipelines to enable continuous security testing.
  • Collaborate with development teams to remediate vulnerabilities and enhance secure coding practices.
  • Provide guidance on secure software development and security architecture.
  • Perform threat modeling to proactively identify security risks.
  • Stay updated on the latest security threats, vulnerabilities, and industry best practices.
  • Develop security policies, standards, and guidelines to strengthen application security.
  • Conduct security training and awareness sessions for developers and stakeholders.

Required Skills and Experience:

  • Strong experience in SAST, DAST, IAST, and SCA tools such as Checkmarx, Fortify, SonarQube, Veracode, Burp Suite, OWASP ZAP, or similar.
  • Hands-on experience with secure coding principles in programming languages like Java, Python, .NET, or JavaScript.
  • Familiarity with CI/CD security, DevSecOps practices, and integrating security tools in pipelines.
  • Knowledge of common application security vulnerabilities and attack vectors (e.g., OWASP Top 10, CWE).
  • Understanding of cloud security concepts in AWS, Azure, or GCP.
  • Experience with penetration testing and manual application security assessments.
  • Strong analytical and problem-solving skills with attention to detail.
  • Excellent communication and stakeholder management skills.

Preferred Qualifications:

  • Relevant security certifications such as OSCP, CISSP, CEH, GWAPT, or CSSLP.
  • Experience with container security, API security, and Kubernetes security.
  • Knowledge of regulatory compliance frameworks such as PCI-DSS, GDPR, HIPAA, NIST, and ISO 27001.
Attach a resume file. Accepted file types are DOCX, and PDF.

We are uploading your application. It may take a few moments to read your resume. Please wait!