We are looking for an experienced Application Security Consultant to perform application security assessments, secure code reviews, and vulnerability management across web, API, and enterprise applications.
Required Qualifications
• 3–5+ years of experience in Application Security, Security Assessments, or Software Development with a security focus
• Strong understanding of common vulnerability classes (e.g., injection, broken authentication, access control, cryptographic issues)
• Ability to script or program to validate findings, automate tasks, or create small security tools
• Hands-on experience with at least one SAST tool (e.g., Snyk, Checkmarx, Fortify, Semgrep)
• Experience reviewing code in at least two modern programming languages
• Understanding of CI/CD, DevOps and DevSecOps approaches and experience working with DevOps tools
• Strong analytical and problem-solving skills
Nice to Have
• Experience supporting SCA/DAST tools,
especially in a role responsible for triaging findings and refining scanning rules.
• Experience reviewing APIs and microservices architectures
• Familiarity with cloud security principles and best practices
• Experience support threat modeling and security design review activities
• Familiarity with security and compliance frameworks (e.g., OWASP ASVS, NIST, ISO 27001, PCI Security Standards Council standards)
• Exposure to Agentic AI or LLM agents and their security considerations
Soft Skills
• Rigorous attention to detail in vulnerability assessment and triage
• Excellent communication skills—able to explain complex security findings to technical and non-technical audiences
• Robust organizational abilities for managing vulnerability data and remediation workflows
• Collaborative problem-solver with a cross-functional mindset
• Self-motivated learner who stays current with emerging secur