Stand out for this role — generate a tailored resume and cover letter in about a minute.
SentinelOne is seeking a senior software security consultant to review code and guide customers on C, C++, Rust, and Java security assessments. You’ll validate findings from agentic scanning, translate technical risk into business impact, and help scale our AI-powered code analysis practice.
You will engage with Wayfinder Frontier AI Services customers end-to-end, scope work, present results to executives, and collaborate with threat hunters and engineering teams to reduce false positives and
Proficiency in at least two of C, C++, Rust, and Java, with a strong understanding of vulnerabilities and secure coding methodologies5+ years in application security or product security with a strong software development backgroundFluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcementStrong threat modeling experience throughout the secure SDLCStrong knowledge of OWASP Top 10, CWE Top 25, and modern authentication infrastructure (SAML, OAuth, OIDC, JWT internals); experience driving an application through ASVS Level 4 verification is a plusProficiency in at least two of C, C++, Rust, and Java, having previously identified and explained vulnerabilities at the framework level, not just the application levelA proven track record translating complex findings into technical and executive-level debriefs; excellent written and verbal communication is essentialHands-on experience authoring custom static-analysis rules and queries for modern SAST engines; familiarity with AI-assisted code review workflows and validating findings produced by automated and agentic analysis pipelinesExperience with AI-accelerated development or code scanning methodologiesExperience delivering customer-facing or consulting-style engagements end-to-end, comfortable in a distributed remote organizationFamiliarity with SOC 2, ISO 27001, or FedRAMP control mappingOSWE, CSSLP, GWAPT, published CVEs, or conference talksReverse engineering of compiled C, C++, Rust, Java (IDA Pro, Binary Ninja, Ghidra)Working depth in Python (Django/Flask) and Node.js (Express) for cross-language reviews