Application Offensive Security Consultant

StaffWorthy

Jersey City (NJ)

On-site

USD 90,000 - 120,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

A financial services company seeks an Application Offensive Security Consultant to conduct secure code reviews and assess vulnerabilities in applications. The candidate should have a strong background in application security, with at least 6 years of experience and proficiency in various programming languages such as Java and Python. Responsibilities include manual code reviews, vulnerability analysis, and collaborating with development teams to ensure secure coding practices. This mid-senior level role offers a dynamic environment with opportunities for influence and growth.

Qualifications

  • Minimum of 5+ years in application security.
  • Minimum of 3+ years of experience in secure code review.
  • Ability to explain vulnerabilities in OWASP Top 10 to any audience.

Responsibilities

  • Perform Manual Secure Code Review against applications.
  • Analyze and identify vulnerabilities in source code.
  • Collaborate with Security Architects and Product Managers.

Skills

Secure code review
Application security
Vulnerability analysis
Java
C#
C/C++
Python
PHP

Education

Bachelors Degree

Tools

Fortify
Veracode
SonarQube

Job description

Application Offensive Security Consultant

Experience level: Mid-senior | Experience required: 6 Years | Education level: Bachelors degree | Job function: Information Technology | Industry: Financial Services | Total position: 1

Why you'll love this job: Being a member of the Application Security team, you will be part of the Technology Risk initiative to support offensive security assessments on applications and provide SME guidance to key projects.

Role Overview

The Application Offensive Security Consultant – Secure Code Reviewer is responsible for providing technical direction and performing secure code review on applications. The person in this role should possess good understanding of application security vulnerabilities, secure coding, software development life cycle (SDLC), offensive security methodology and SAST/DAST.

Primary Responsibilities
  • Perform Manual Secure Code Review against applications.
  • Analyze and identify vulnerabilities in source code using manual analysis techniques.
  • Coordinate with application development teams to collect the application details.
  • Provide the vulnerability information in the predefined report format after performing the testing using manual methodology.
  • Assist the developers and business teams in detailing the vulnerabilities reported along with the recommendations for remediation.
  • Align risk and control processes into day-to-day responsibilities to monitor and mitigate risk; escalates appropriately.
  • Generate reports on assessment findings and summarize to facilitate remediation, document technical issues identified during security assessments.
  • Perform threat modeling, design, and code views to assess security implications and requirements.
  • Be a subject matter expert and respond to any security engineering questions or requests related to Application Defense enhancements.
  • Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product.
Qualifications
  • Minimum of 3+ years of experience in secure code review.
  • Minimum of 5+ years in application security.
  • Experience in performing manual secure code review.
  • Bachelors Degree and/or equivalent experience.
  • Minimum of 5 years of experience in application security.
  • Minimum of 3 years of detecting and analyzing vulnerabilities in at least two of the following languages: Java, C#, C/C++, Python, PHP.
  • Ability to explain vulnerabilities and weaknesses in OWASP Top 10 and SANS Top 25 to any audience and discuss effective defensive techniques.
  • Proficiency with application security best practices with focus on secure coding.
  • Ability to work under pressure, multitask and be flexible.
  • Experience in conducting analysis using commercial tools such as Fortify, Veracode, SonarQube or related tool.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Offensive Security Consultant
Application Offensive Security Consultant

Pipe Recruit • Jersey City (NJ)

On-site
USD 83,000 - 165,000
Lead Secure Code Review: Offensive Security for Applications
Lead Secure Code Review: Offensive Security for Applications

StaffWorthy • Jersey City (NJ)

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Application Security Engineer | Remote
Application Security Engineer | Remote

Crossing Hurdles • United States

On-site
GBP 50,000 - 70,000
Lead Consultant – Application Security
Lead Consultant – Application Security

SmartRecruiters, Inc. • Exton (PA)

On-site
USD 100,000 - 130,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

Infosys • Richardson (TX)

On-site
USD 110,000 - 170,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
Application Security Vulnerability Analyst
Application Security Vulnerability Analyst

Perennial Resources International • New York (NY)

On-site
USD 110,000 - 160,000
Application Security Architect
Application Security Architect

US Tech Solutions • Jersey City (NJ)

On-site
USD 90,000 - 120,000