We are looking for an experienced Application Security Consultant to perform application security assessments, secure code reviews, and vulnerability management across web, API, and enterprise applications.
Required Qualifications
- 3–5+ years of experience in Application Security, Security Assessments, or Software Development with a security focus
- Strong understanding of common vulnerability classes (e.g., injection, broken authentication, access control, cryptographic issues)
- Ability to script or program to validate findings, automate tasks, or create small security tools
- Hands-on experience with at least one SAST tool (e.g., Snyk, Checkmarx, Fortify, Semgrep)
- Experience reviewing code in at least two contemporary programming languages
- Understanding of CI/CD, DevOps and DevSecOps approaches and experience working with DevOps tools
- Strong analytical and problem-solving skills
________________________________________
Nice to Have
- Experience supporting SCA/DAST tools,
especially in a role responsible for triaging findings and refining scanning rules.
- Experience reviewing APIs and microservices architectures
- Familiarity with cloud security principles and best practices
- Experience support threat modeling and security design review activities
- Familiarity with security and compliance frameworks (e.g., OWASP ASVS, NIST, ISO 27001, PCI Security Standards Council standards)
- Exposure to Agentic AI or LLM agents and their security considerations
________________________________________
Soft Skills
- Rigorous attention to detail in vulnerability assessment and triage
- Excellent communication skills—able to explain complex security findings to technical and non-technical audiences
- Strong organizational abilities for managing vulnerability data and remediation workflows
- Collaborative problem-solver with a cross-functional mindset
- Self-motivated learner who stays current with emerging security threats