Security Consultant (Secure Code Review Practice)

NetSPI

Pune City

On-site

INR 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading cybersecurity company is seeking a Security Consultant for their Secure Code Review practice. The ideal candidate will have experience in source code review, application security assessments, and strong consulting skills. This role involves working with developers to identify and remediate vulnerabilities, ensuring high standards of security and ethics.

Qualifications

  • 1-6 years of hands-on Source Code Review experience.
  • Familiarity with secure coding guidelines and ability to analyze source code.

Responsibilities

  • Experience using and triaging findings from SAST tools.
  • Identify and review third-party vulnerabilities in source code.
  • Provide clear remediation guidance for identified vulnerabilities.

Skills

Problem Solving
Client Service
Written and Verbal Communications
Consulting Skills

Education

Bachelor’s degree in computer science/engineering

Tools

Checkmarx
Snyk
Semgrep
Maven
Gradle
npm
pip

Job description

Security Consultant (Secure Code Review Practice)

Join to apply for the Security Consultant (Secure Code Review Practice) role at NetSPI

Security Consultant (Secure Code Review Practice)

1 day ago Be among the first 25 applicants

Join to apply for the Security Consultant (Secure Code Review Practice) role at NetSPI

Get AI-powered advice on this job and more exclusive features.

NetSPI is the proactive security solution used to discover, prioritize, and remediate security vulnerabilities of the highest importance, so businesses can protect what matters most. NetSPI secures the most trusted brands on Earth through Penetration Testing as a Service (PTaaS), External Attack Surface Management (EASM), Cyber Asset Attack Surface Management (CAASM), and Breach and Attack Simulation (BAS). Leveraging a unique combination of dedicated security experts, intelligent process, and advanced technology, NetSPI brings a proactive approach to cybersecurity with more clarity, speed, and scale than ever before.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

NetSPI is seeking Security Consultants for our Secure Code Review practice. These individuals will primarily serve as a resource for delivery of client assessment services and contribute to practice development. Individuals who are passionate about findings vulnerabilities in source code and identifying secure coding best practices should consider applying.

This position requires an understanding of technology, enterprise security and risk management. Incumbent should have some experience with application security assessment and testing, as well as demonstrating competencies in problem solving, client service, written and verbal communications, and project execution. Incumbent should adhere to high standards of ethics and integrity and display professionalism. Finally, incumbent should possess strong consulting skills.

Responsibilities:

  • Experience using, configuring, and triaging findings from Static Application Security Testing (SAST) tools like Checkmarx and Semgrep.
  • Proven track record in delivering several assessments involving static analysis and manual code review. The consultant excels in taint tracking within the code's data and control flow (source to sink analysis) and are skilled in identifying any mitigation controls that may affect the exploitability of a particular finding.
  • Experience in identifying and reviewing third-party vulnerabilities in source code using tools such as Snyk, Semgrep and Black Duck. The consultant is adept in researching CVEs to identify exploitability factors and perform reachability analysis to determine if a particular library poses a risk.
  • Skilled in using build tools (Maven, Gradle) & package managers (npm, pip).
  • Proven ability to work effectively with developers and application stakeholders. Consultant excels at providing clear remediation guidance and contextual explanations for identified vulnerabilities.
  • Leveraging automated and manual analysis to identify suspicious patterns in source code and identify potential points of interest that can be exploited by malicious actors to launch attack or exfiltrate data.
  • Train and assist developers in describing and remediating existing vulnerabilities.

Minimum Qualifications:

  • 1-6 years of hands-on Source Code Review experience.
  • Familiarity with secure coding guidelines and ability to analyze and review source code in at least one server-side programming language.
  • Knowledge of exploiting web applications and understanding of the OWASP Top 10 issues, including ability to identify and remediate vulnerabilities in source code.
  • Bachelor’s degree in computer science/ engineering or equivalent.

Preferred Qualifications:

  • Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx, Appscan Source, Veracode, Coverity, Fortify and SonarQube.
  • Good to have programming experience in at least one server-side programming language.
  • Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience.
  • Master’s degree in computer science/ engineering or equivalent.

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Consulting
  • Industries
    IT Services and IT Consulting

Referrals increase your chances of interviewing at NetSPI by 2x

Get notified about new Security Consultant jobs in Pune, Maharashtra, India.

Manager Enterprise Security (Privileged Access Management)
Security & Loss Prevention Manager, INSLP
Senior Security Consultant (Thick Application Penetration Testing)
Senior Manager Enterprise Security (Privileged Access Management)
Incident Response & Investigations Manager - Information Security
SAP GRC/ Security- Manager/ Associate Director
Senior Delivery Manager - Information Security/Senior Delivery Manager - Information Security
Senior Delivery Manager - Information Security/Senior Delivery Manager - Information Security
Senior Domain Manager Cyber Security - IT
Senior Delivery Manager - Information Security/Senior Delivery Manager - Information Security

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Consultant (Web Application Penetration Tester)
Security Consultant (Web Application Penetration Tester)

NetSPI • Pune City

On-site
INR 1,200,000 - 1,800,000
Senior Security Consultant (Secure Code Review)
Senior Security Consultant (Secure Code Review)

NetSPI • Maharashtra

On-site
INR 1,800,000 - 2,800,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI • Maharashtra

Hybrid
INR 900,000 - 1,400,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,400,000 - 2,000,000
Security Consultant II (Web Application Penetration Tester)
Security Consultant II (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,500,000 - 2,000,000
Senior Application Security Specialist
Senior Application Security Specialist

[24]7.ai • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Senior Security Specialist
Senior Security Specialist

techvantage.ai • Thiruvananthapuram

On-site
INR 1,500,000 - 2,500,000
High visibility in a growing function
Opportunity to work with innovative technology
Competitive compensation
Security Consultant
Security Consultant

Gruve • Mumbai City

On-site
INR 800,000 - 1,200,000
Senior Software Engineer - Security
Senior Software Engineer - Security

LogiNext • Mumbai City

On-site
INR 1,500,000 - 2,500,000
Security Architect
Security Architect

Accenture in India • Bengaluru

On-site
INR 1,500,000 - 2,500,000