Senior Security Consultant (Secure Code Review)

NetSPI

Maharashtra

On-site

INR 1,800,000 - 2,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NetSPI in Pune, MH is seeking a Senior Security Consultant specializing in Secure Code Review to deliver client assessments and advance our practice. You will identify security vulnerabilities in source code across Java, .Net, JavaScript, Python, and more, and guide remediation with clear, actionable advice.

The role emphasizes hands-on analysis of static results from SAST tools, taint tracking, and collaboration with developers and stakeholders to improve secure coding practices and reduce

Qualifications

  • Minimum of two years of hands-on secure code review experience across multiple languages and frameworks.
  • Knowledge of the OWASP Top 10 issues and secure coding guidelines.
  • Bachelor’s degree in computer science/engineering or equivalent.

Responsibilities

  • Identify security vulnerabilities in source code across languages and frameworks.
  • Use, configure, and triage findings from SAST tools like Veracode, Checkmarx or Semgrep.
  • Deliver assessments involving static analysis and manual code review.
  • Perform reachability analysis to assess exploitability of vulnerable libraries.
  • Understand build tools (Maven, Gradle) and package managers (npm, pip) to navigate projects.
  • Collaborate with developers and stakeholders to provide remediation guidance and training.

Skills

Application security assessment
Problem solving
Client service
Written and verbal communications
Project execution
Strong consulting skills
Secure coding

Education

Bachelor's degree in computer science/engineering or equivalent
Master's degree (preferred)

Tools

Veracode
Checkmarx
Semgrep
AppScan Source
Coverity
Fortify
SonarQube
Maven
Gradle
npm
pip

Job description

Title: Senior Security Consultant (Secure Code Review)

Location: Pune, MH

NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world‑class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep‑dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001.

Join the mission as a Security Consultant (Secure Code Review). These individuals will primarily serve as a resource for delivery of client assessment services and contribute to practice development. Individuals who are passionate about findings vulnerabilities in source code and identifying secure coding best practices should consider applying.

Core Competencies
  • This position requires an understanding of technology, enterprise security and risk management.
  • Incumbent should have experience with application security assessment and testing, as well as demonstrate competencies in problem solving, client service, written and verbal communications, and project execution. Incumbent should adhere to high standards of ethics, integrity and display professionalism.
  • Finally, incumbent should possess strong consulting skills.
Primary Duties
  • Proven ability to identify security vulnerabilities in source code across various programming languages and frameworks including Java, .Net, JavaScript, Python, and more.
  • Experience using, configuring, and triaging findings from Static Application Security Testing (SAST) tools such as Veracode, Checkmarx or Semgrep.
  • Proven track record in delivering several assessments involving static analysis and manual code review. The consultant should excel in taint tracking across data and control flow paths from source to sink and be skilled at identifying mitigation controls that may affect a finding's exploitability.
  • Experience identifying and reviewing third‑party vulnerabilities in source code using software composition analysis tools. The consultant should be adept at researching CVEs to assess exploitability factors and perform reachability analysis to determine whether a vulnerable library poses an actual risk.
  • Strong understanding of build tools (Maven, Gradle) and package managers (npm, pip), with the ability to navigate project structures and dependency configurations during review.
  • Proven ability to work effectively with developers and application stakeholders, providing clear remediation guidance and contextual explanations for identified vulnerabilities.
  • Ability to train and mentor developers on understanding, describing, and remediating vulnerabilities identified during engagements.
Minimum Qualifications
  • Minimum of two years of hands‑on secure code review experience across multiple languages and frameworks, with proficiency in analyzing source code against established secure coding guidelines.
  • Knowledge of exploiting web applications and understanding of the OWASP Top 10 issues, including ability to identify and remediate vulnerabilities in source code.
  • Bachelor’s degree in computer science/engineering or equivalent.
Preferred Qualifications
  • Experience in detecting, analyzing, and providing recommendation guidance on security vulnerabilities in at least one of the following languages: Java, C#, PHP, Python, Perl, C/C++, SQL, JavaScript.
  • Hands‑on experience conducting security focused static analysis using commercial SAST tools such as Veracode, Checkmarx, Semgrep, AppScan Source, Coverity, Fortify, or SonarQube.
  • Professional programming experience in at least one server‑side programming language.
  • Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience.
  • Master’s degree in computer science/engineering or equivalent.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Consultant (Secure Code Review Practice)
Security Consultant (Secure Code Review Practice)

NetSPI • Pune City

On-site
INR 800,000 - 1,200,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI • Maharashtra

Hybrid
INR 900,000 - 1,400,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,400,000 - 2,000,000
Security Consultant II (Web Application Penetration Tester)
Security Consultant II (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,500,000 - 2,000,000
Sr. Consultant – Code Review + Web App | Experience: 5+ Years
Sr. Consultant – Code Review + Web App | Experience: 5+ Years

Aujas Networks Pvt. Ltd. • Bengaluru

On-site
INR 600,000 - 1,000,000
DevSecOps Associate - Source Code Review Security
DevSecOps Associate - Source Code Review Security

ESP Engineered • Maharashtra

On-site
INR 600,000 - 1,200,000
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Senior Security Consultant - Attack & Pentest
Senior Security Consultant - Attack & Pentest

Varutra • Hyderabad

On-site
INR 800,000 - 1,200,000
Security Consultant (Web Application Penetration Tester)
Security Consultant (Web Application Penetration Tester)

NetSPI • Pune City

On-site
INR 1,200,000 - 1,800,000