Application Security Consultant

vTech Solution Inc
Richmond, VA, United States
8 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

.NET Framework Business Logic C Sharp (Programming Language) Static Program Analysis Open Web Application Security Systems Development Life Cycle Secure Coding Software Engineering Data Streaming Web Applications Enterprise Software Applications Software Security
+2 more
GWAPT Static Application Security Testing

Job description

The Application Security Senior Consultant serves as the technical authority responsible for conducting expert manual secure code reviews and security assessments of enterprise applications, primarily focusing on large C#/.NET codebases. This role identifies security weaknesses that automated tools may miss and ensures the accuracy and actionability of findings delivered to stakeholders. The consultant leads architecture reviews, assesses multiple security dimensions, prioritizes risks, and provides detailed remediation guidance to enhance the security posture of critical financial and transaction-processing applications. Responsibilities:

  • Lead architecture walkthroughs with application and development subject matter experts (SMEs).
  • Establish and validate read-only source code access under least privilege principles.
  • Create technology and framework inventories for each application assessed.
  • Develop criticality-weighted coverage plans focusing manual review on business-critical code paths.
  • Perform manual secure code reviews across architecture, access control, data protection, business logic, and security-sensitive code paths.
  • Map trust boundaries, data flows, and external system interactions per application.
  • Construct and test abuse cases against critical business rules and transaction logic.
  • Trace and verify authorization enforcement workflows and separation of duties.
  • Assess cryptographic implementations, key lifecycle, and secrets management.
  • Escalate confirmed high-impact findings within 4 business hours.
  • Assign CVSS v3.1 base and environmental ratings to findings and agree on environmental context.
  • Author prescriptive remediation guidance specific to the C#/.NET codebase.
  • Identify root-cause patterns across applications and contribute to technical and strategic report sections.
  • Lead technical findings discussions and support report presentations to leadership.

Requirements

  • Minimum 6 years of experience in application security.
  • Expertise in secure code review of enterprise web applications.
  • Strong knowledge of web application and API security.
  • Hands-on experience with C# and .NET development environments.
  • Proficiency in manual code analysis techniques.
  • Experience with commercial static analysis (SAST) tools.
  • Understanding of authentication and authorization architectures.
  • Knowledge of secure Software Development Life Cycle (SDLC) practices.

Preferred Skills & Certifications:

  • Relevant application security or offensive security certifications such as OSWE, GWAPT, CSSLP, or CISSP.
  • Experience delivering services to the public sector or Commonwealth of Virginia.
  • Familiarity with security standards and frameworks including NIST SP 800-53, COV SEC530, OWASP ASVS, and CWE.
  • Domain knowledge of financial or transaction-processing applications.

Special Considerations:

  • Immediate escalation of high-impact security issues within 4 business hours is required.
  • Read-only source code access must be established and maintained under least privilege principles.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:50 min

Electronic diagnostic software tools and factory production flashing

Denis Grahovac · World Congress 2021

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:05 min

Differences between RPA platforms and the .NET framework

Maria Doina Irimias · LIVE

Videos

See all

Related articles

See all