Application Security Testing
SAST Advanced: Hands-on experience performing static application security testing, reviewing code-level findings, and validating scan results.
DAST – Advanced: Experience executing agile application security testing for web applications and APIs and analyzing runtime vulnerabilities.
SCA – Advanced: Experience identifying and triaging open-source and third-party component vulnerabilities.
False Positive Analysis – Advanced: Robust ability to investigate scanner findings and accurately determine true positives versus false positives.
Vulnerability Triaging – Advanced: Experience assessing vulnerabilities based on severity, exploitability, business impact, and remediation priority.
Security Tools & Platforms
Checkmarx – Advanced: Hands-on experience configuring, tuning, and executing Checkmarx scans in enterprise environments.
AppScan – Advanced: Experience setting up and running AppScan assessments for web applications and APIs.
Familiarity with scan policy configuration, exclusions, and tuning to improve result accuracy and reduce noise.
Understanding of integrating security testing tools into CI/CD pipelines and development workflows.
Vulnerability Management & Remediation
Ability to document vulnerabilities clearly and concisely for technical and non-technical stakeholders.
Experience providing remediation guidance aligned to secure coding practices and enterprise security standards.
Strong understanding of common application vulnerabilities such as OWASP Top 10 issues, insecure dependencies, and authentication/authorization flaws.
Ability to support revalidation and closure of remediated findings.
Collaboration & Communication
Ability to work effectively with cross-functional teams including developers, architects, QA teams, DevOps engineers, and security stakeholders.
Strong analytical, problem-solving, and written/verbal communication skills.
Ability to communicate security findings, risk implications, and remediation guidance in a explicit and actionable manner.
Experience operating in client-facing or enterprise delivery environments is preferred.
📌 Application Security Testing Consultant With Sast And Dast Hyderabad
🏢 Cloudxtreme
📍 Hyderabad
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.