Enable job alerts via email!

Senior Security Consultant (Secure Code Review + Web Application Penetration Testing)

NetSPI Inc.

Minneapolis (MN)

Remote

USD 100,000 - 130,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading cybersecurity firm seeks a Senior Security Consultant to deliver secure code reviews and web application penetration testing. This role requires substantial experience in application security, particularly secure code review and penetration testing, along with strong problem-solving and communication skills. The successful candidate will work remotely, contributing to vital security assessments and mentoring fellow team members while maintaining a proactive approach to security solutions.

Qualifications

  • Minimum of 3-5 years of experience in application security.
  • Exceptional knowledge of Burp Suite and OWASP Top 10.
  • Ability to communicate risks and business impact effectively.

Responsibilities

  • Conduct secure code reviews and web app penetration testing.
  • Exploit vulnerabilities and train developers on security best practices.
  • Provide oversight to peers and mentor team members.

Skills

Application Security
Secure Code Review
Penetration Testing
Problem Solving
Client Service
Communication

Education

Bachelor’s degree in Computer Science or related field

Tools

Burp Suite
SAST tools

Job description

Senior Security Consultant (Secure Code Review + Web Application Penetration Testing)

Job Category: Services

Requisition Number: SENIO001571

Apply now

  • Full-Time
  • Remote
Locations

Showing 1 location

Remote - US
241 N 5th Avenue
Suite 1200
Minneapolis, MN 55401, USA

Remote - US
241 N 5th Avenue
Suite 1200
Minneapolis, MN 55401, USA

NetSPI is the proactive security solution used to discover, prioritize, and remediate security vulnerabilities of the highest importance, so businesses can protect what matters most. NetSPI secures the most trusted brands on Earth through Penetration Testing as a Service (PTaaS), External Attack Surface Management (EASM), Cyber Asset Attack Surface Management (CAASM), and Breach and Attack Simulation (BAS). Leveraging a unique combination of dedicated security experts, intelligent process, and advanced technology, NetSPI brings a proactive approach to cybersecurity with more clarity, speed, and scale than ever before.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team atwww.netspi.com/careers.

NetSPI is seeking a Senior Security Consultant who will serve as a resource for delivery of secure code review and web application penetration assessment. This position requires an understanding of various web technologies, enterprise secure development and risk management. In addition, it requires experience with application security assessments/testing, as well as demonstrated competencies in problem solving, client service, written/verbal communication, and project execution.

Responsibilities:

  • Conduct in-depth penetration testing and secure code review assessments on web applications
  • Dynamically exploit vulnerabilities found in codebase and correlate insecure coding practices into dynamic application vulnerabilities
  • Deliver secure code review assessment on programming languages such as Java, C#, Python, C/C++, Perl, PHP
  • Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
  • Train and assist developers in writing secure software and remediating existing vulnerabilities
  • Provide oversight to peers on service lines through QA process
  • Mentor and assist team members in effectively delivering assessments and enhancing skillsets
  • Present detailed penetration test findings to clients and assist in remediation planning
  • Engage in research to develop new penetration testing methods, tools, and innovative exploit techniques
  • Contribute to the cybersecurity community through tools, presentations, white papers, and blogging
  • Maintain consistency with other internal requirements related to day-to-day administration tasks (time keeping, status updates to clients, etc.)

Minimum Qualifications:

  • Minimum of 3-5 years of experience in application security including both secure code review and web application penetration testing
  • Exceptional familiarity in all Burp Suite functions. Published Burp extensions and ability to create new Burp Suite extensions preferred
  • Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code
  • Ability to explain risk and business impact of security vulnerabilities to variety of audience
  • Bachelor’s degree or higher, preferably in Computer Science, Engineering, Mathematics, IT, or a related field; equivalent experience will also be considered.
  • Willingness to travel up to 25%

Preferred Qualifications:

  • Experience in detecting, analyzing and providing recommendation guidance on security vulnerabilities using SAST and/or manual secure code review in at least two of the following languages: Java, C#, PHP, Python, C/C++
  • Experience in software development in at least one server-side programming language

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.

Qualifications
Skills
Behaviors

:

Motivations

:

Education
Experience
Licenses & Certifications

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Security Consultant (Secure Code Review + Web Application Penetration Testing)

NetSPI Inc.

Minneapolis null

Remote

Remote

USD 80.000 - 130.000

Full time

30+ days ago

Senior Security Consultant

Tenable Network Security, Inc.

null null

Remote

Remote

USD 100.000 - 150.000

Full time

5 days ago
Be an early applicant

Information Security Consultant (m/w/d) - bundesweit remote oder hybrid

ZipRecruiter

Cologne null

Remote

Remote

EUR 80.000 - 120.000

Full time

3 days ago
Be an early applicant

Senior Security Advisor - Access Management (Remote in the U.S.)

GuidePoint Security

null null

Remote

Remote

USD 100.000 - 150.000

Full time

3 days ago
Be an early applicant

Senior Security Advisor - Access Management (Remote in the U.S.)

Davita Inc.

null null

Remote

Remote

USD 120.000 - 160.000

Full time

3 days ago
Be an early applicant

Senior SAP Security Consultant

Infosys Limited

null null

Remote

Remote

USD 66.000 - 103.000

Full time

4 days ago
Be an early applicant

Senior Security Advisor - Access Management (Remote in the U.S.)

GuidePoint Security

Dallas null

Remote

Remote

USD 110.000 - 160.000

Full time

4 days ago
Be an early applicant

Senior Information Security Consultant

Zync.

Galloway Township null

Remote

Remote

USD 90.000 - 120.000

Full time

4 days ago
Be an early applicant

Senior Cloud Security Consultant

Davita Inc.

Westminster null

Remote

Remote

USD 120.000 - 160.000

Full time

5 days ago
Be an early applicant