SAST/DAST Application Security Consultant (Pen Testing)

Alignity Solutions

Hyderabad

Hybrid

INR 1,200,000 - 1,800,000

Part time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Alignity Solutions is seeking a Senior SAST/DAST Application Security Consultant specializing in Penetration Testing. The role is hybrid, offering challenging security engagements and long-term project stability with immediate joining for the right candidate.

The consultant will integrate SAST/DAST tools into CI/CD, perform comprehensive security assessments, and guide development teams on secure coding and remediation strategies while staying current with OWASP and industry trends.

Qualifications

  • Bachelor's degree or higher in CS, Cybersecurity, Information Security or related field.
  • CSSLP, CEH or equivalent certifications preferred.
  • Experience with cloud-native applications and container security.

Responsibilities

  • Integrate SAST and DAST tools into CI/CD pipelines to automate security testing.
  • Perform static and dynamic assessments to identify OWASP Top 10 risks.
  • Analyze results, triage findings, and provide remediation guidance to developers.
  • Collaborate with developers to promote secure coding practices and reviews.
  • Define security roles and ownership between Deloitte and client stakeholders.
  • Track vulnerabilities through lifecycle and ensure remediation.
  • Conduct RCA workshops for security findings and recurring issues.
  • Prepare and publish security testing reports, dashboards, and metrics.
  • Stay current with threats, OWASP standards, and tool advancements.

Skills

SAST
DAST
CI/CD pipelines
OWASP Top 10
SSDLC
Vulnerability remediation
Threat modeling
Jenkins

Education

Bachelor's degree or higher in CS/Cybersecurity
CSSLP or CEH certification

Tools

Checkmarx
Veracode
Fortify
Burp Suite
OWASP ZAP

Job description

SAST/DAST Application Security Consultant (Pen Testing)

Do you love a career where you Experience , Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.

Learn how we are redefining the meaning of work , and be a part of the team raved by Clients, Job-seekers and Employees.

If you are aSAST/DAST Application Security Consultant looking for excitement, challenge and stability in your work, then you would be glad to come across this page.

We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.

Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.

Role: SAST/DAST Application Security Consultant - Penetration Testing

Work Mode: Hybrid

Type: Contract to Hire

Notice Period:Immediate Joiners

Requirements

As a Senior Consultant – SAST/DAST/Penetration Testing , the candidate will be responsible for:

  • Integrating SAST and DAST security tools into CI/CD pipelines to automate application security testing throughout the development lifecycle.
  • Performing regular static and dynamic application security assessments to identify vulnerabilities, including SQL Injection, Cross-Site Scripting (XSS), and other OWASP Top 10 risks.
  • Analyzing security scan results, triaging and validating findings , and providing actionable remediation guidance to development teams.
  • Collaborating with developers to promote secure coding practices and support secure design and application security reviews.
  • Defining and maintaining security roles, responsibilities, and ownership between Deloitte and client stakeholders for security test preparation, execution, and support.
  • Tracking vulnerabilities through their lifecycle and ensuring findings are reported, remediated, and validated in accordance with organizational policies and client requirements.
  • Conducting Root Cause Analysis (RCA) workshops for security findings and recurring vulnerabilities.
  • Preparing and publishing security testing reports, dashboards, and performance metrics .
  • Staying current with emerging application security threats, industry trends, OWASP standards, and advancements in SAST/DAST tools and methodologies.
Required Skills

Hands-on experience with leading SAST and DAST tools , including:

  • Checkmarx
  • Veracode
  • Fortify
  • Burp Suite
  • OWASP ZAP
  • Strong understanding of Secure Software Development Lifecycle (SSDLC) principles.
  • Strong knowledge of OWASP Top 10 vulnerabilities and application security best practices.
  • Experience integrating security testing into CI/CD pipelines , including Jenkins, Azure DevOps, and GitLab CI.
  • Ability to interpret, validate, prioritize, and communicate vulnerability findings and remediation recommendations to technical and non-technical stakeholders.
  • Strong understanding of both white-box (SAST) and black-box (DAST) testing methodologies.
  • Practical experience in application security and vulnerability management.
Qualifications
  • Bachelor's degree or higher in Computer Science, Cybersecurity, Information Security , or a related field, or equivalent professional experience.
  • Security certifications such as CSSLP, CEH, or equivalent are preferred.
  • Experience with cloud-native application security and container security .
  • Knowledge of regulatory and compliance requirements related to application security.
Good to Have
  • Experience participating in or conducting Security Architecture Reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
  • Proficiency in Threat Modeling methodologies such as STRIDE, PASTA, or equivalent frameworks.
  • Ability to systematically identify, document, assess, and prioritize potential threats and attack vectors .
  • Experience translating threat-model findings into actionable SAST/DAST test cases .
  • Ability to ensure identified threats are adequately tested, remediated, and validated.
  • Experience with DevSecOps, cloud security, container security, API security, and modern application architectures .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer (SAST/DAST)
DevSecOps Engineer (SAST/DAST)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Penetration Tester
Penetration Tester

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru Urban

On-site
INR 2,600,000 - 3,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Security Penetration Testing Consultant
Security Penetration Testing Consultant

Withum • Bengaluru

On-site
INR 900,000 - 1,300,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000