Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you. Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees. Jobseeker Video Testimonials Employee Glassdoor Reviews
Are you a SAST/DAST Application Security Consultant looking for excitement, challenge and stability in your work, then you would be glad to come across this page. We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Role: SAST/DAST Application Security Consultant
- Location: Hyderabad
- Experience: 3-8 Years
- Work Mode: Hybrid
- Type: Contract to Hire
- Notice Period: Immediate Joiners
Roles & Responsibilities
- Integrate SAST and DAST tools into CI/CD pipelines to automate security testing throughout the development lifecycle.
- Perform regular static (SAST) and dynamic (DAST) security assessments on applications to identify vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.
- Analyze scan results, triage findings, and provide actionable remediation guidance to development teams.
- Collaborate with developers to ensure secure coding practices and support secure design reviews.
- Define and maintain security roles, responsibilities, and ownership between Deloitte and client stakeholders for test preparation, execution, and support.
- Ensure that vulnerabilities are tracked, reported, and resolved in accordance with organizational policies and client requirements.
- Conduct root cause analysis (RCA) workshops and publish performance and security testing reports.
- Stay current with industry trends, emerging threats, and advancements in SAST/DAST tools and methodologies.
Required Skills
- Hands-on experience with leading SAST and DAST tools (e.g., Checkmarx, Veracode, Fortify, Burp Suite, OWASP ZAP).
- Strong understanding of secure software development lifecycle (SSDLC) principles and OWASP Top 10 vulnerabilities.
- Experience integrating security testing into CI/CD pipelines (e.g., Jenkins, Azure DevOps, GitLab CI).
- Ability to interpret and communicate vulnerability findings and remediation steps to technical and non-technical stakeholders.
- Familiarity with both black-box (DAST) and white-box (SAST) testing methodologies.
Qualifications
- Bachelor's degree or higher in Computer Science, or equivalent experience.
- Security certifications such as CSSLP, CEH, or similar.
- Experience with cloud-native application security and container security.
- Knowledge of regulatory and compliance requirements related to application security.
Good to have
- Experience participating in or conducting security architecture reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
- Proficiency in performing threat modeling exercises (e.g., using STRIDE, PASTA, or other frameworks) to systematically identify, document, and prioritize potential threats and attack vectors in applications and systems.
- Skill in translating threat model findings into actionable SAST/DAST test cases and ensuring that identified threats are adequately tested and mitigated.
Benefits
Visit us at http://alignity.io/careers. Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.