Application Offensive Security Consultant

StaffWorthy

Jersey City (NJ)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A financial services company seeks an Application Offensive Security Consultant to conduct secure code reviews and assess vulnerabilities in applications. The candidate should have a strong background in application security, with at least 6 years of experience and proficiency in various programming languages such as Java and Python. Responsibilities include manual code reviews, vulnerability analysis, and collaborating with development teams to ensure secure coding practices. This mid-senior level role offers a dynamic environment with opportunities for influence and growth.

Qualifications

  • Minimum of 5+ years in application security.
  • Minimum of 3+ years of experience in secure code review.
  • Ability to explain vulnerabilities in OWASP Top 10 to any audience.

Responsibilities

  • Perform Manual Secure Code Review against applications.
  • Analyze and identify vulnerabilities in source code.
  • Collaborate with Security Architects and Product Managers.

Skills

Secure code review
Application security
Vulnerability analysis
Java
C#
C/C++
Python
PHP

Education

Bachelors Degree

Tools

Fortify
Veracode
SonarQube

Job description

Application Offensive Security Consultant

Experience level: Mid-senior | Experience required: 6 Years | Education level: Bachelors degree | Job function: Information Technology | Industry: Financial Services | Total position: 1

Why you'll love this job: Being a member of the Application Security team, you will be part of the Technology Risk initiative to support offensive security assessments on applications and provide SME guidance to key projects.

Role Overview

The Application Offensive Security Consultant – Secure Code Reviewer is responsible for providing technical direction and performing secure code review on applications. The person in this role should possess good understanding of application security vulnerabilities, secure coding, software development life cycle (SDLC), offensive security methodology and SAST/DAST.

Primary Responsibilities
  • Perform Manual Secure Code Review against applications.
  • Analyze and identify vulnerabilities in source code using manual analysis techniques.
  • Coordinate with application development teams to collect the application details.
  • Provide the vulnerability information in the predefined report format after performing the testing using manual methodology.
  • Assist the developers and business teams in detailing the vulnerabilities reported along with the recommendations for remediation.
  • Align risk and control processes into day-to-day responsibilities to monitor and mitigate risk; escalates appropriately.
  • Generate reports on assessment findings and summarize to facilitate remediation, document technical issues identified during security assessments.
  • Perform threat modeling, design, and code views to assess security implications and requirements.
  • Be a subject matter expert and respond to any security engineering questions or requests related to Application Defense enhancements.
  • Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product.
Qualifications
  • Minimum of 3+ years of experience in secure code review.
  • Minimum of 5+ years in application security.
  • Experience in performing manual secure code review.
  • Bachelors Degree and/or equivalent experience.
  • Minimum of 5 years of experience in application security.
  • Minimum of 3 years of detecting and analyzing vulnerabilities in at least two of the following languages: Java, C#, C/C++, Python, PHP.
  • Ability to explain vulnerabilities and weaknesses in OWASP Top 10 and SANS Top 25 to any audience and discuss effective defensive techniques.
  • Proficiency with application security best practices with focus on secure coding.
  • Ability to work under pressure, multitask and be flexible.
  • Experience in conducting analysis using commercial tools such as Fortify, Veracode, SonarQube or related tool.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Offensive Security Consultant jersey city, nj
Application Offensive Security Consultant jersey city, nj

ESR Healthcare • Jersey City (NJ)

On-site
USD 96,000 - 152,000
CTF participation
Penetration testing certs
Red team training
Application Offensive Security Consultant
Application Offensive Security Consultant

Pipe Recruit • Jersey City (NJ)

Hybrid
USD 83,000 - 165,000
Lead Secure Code Review: Offensive Security for Applications
Lead Secure Code Review: Offensive Security for Applications

StaffWorthy • Jersey City (NJ)

On-site
USD 90,000 - 120,000
Application Security Engineer | Remote
Application Security Engineer | Remote

Crossing Hurdles • United States

Remote
GBP 50,000 - 70,000
Lead Consultant – Application Security (Min 10+ Years Experience)
Lead Consultant – Application Security (Min 10+ Years Experience)

Career Guidant Inc. • Exton (PA)

On-site
USD 100,000 - 130,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Lead Consultant – Application Security
Lead Consultant – Application Security

Avance Consulting Services • Exton (PA)

On-site
USD 100,000 - 130,000
Application Security Hardening Specialist
Application Security Hardening Specialist

Featmate • Germany (OH)

On-site
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Cherry Hills Village (CO)

On-site
USD 80,000 - 110,000