> Markdown version of [/jobs/ext/2590681-application-security-consultant](https://www.wearedevelopers.com/jobs/ext/2590681-application-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Consultant - **Company:** vTech Solution Inc - **Location:** Richmond, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** .NET Framework, Business Logic, C Sharp (Programming Language), Static Program Analysis, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Data Streaming, Web Applications, Enterprise Software Applications, Software Security, GWAPT, Static Application Security Testing - **Published:** August 30, 2026 - **Apply:** https://www.careerjet.com/jobad/usde2a3f63356bbe88384ba0e633288f3b ## About the Role * Minimum 6 years of experience in application security. * Expertise in secure code review of enterprise web applications. * Strong knowledge of web application and API security. * Hands-on experience with C# and .NET development environments. * Proficiency in manual code analysis techniques. * Experience with commercial static analysis (SAST) tools. * Understanding of authentication and authorization architectures. * Knowledge of secure Software Development Life Cycle (SDLC) practices. Preferred Skills & Certifications: * Relevant application security or offensive security certifications such as OSWE, GWAPT, CSSLP, or CISSP. * Experience delivering services to the public sector or Commonwealth of Virginia. * Familiarity with security standards and frameworks including NIST SP 800-53, COV SEC530, OWASP ASVS, and CWE. * Domain knowledge of financial or transaction-processing applications. Special Considerations: * Immediate escalation of high-impact security issues within 4 business hours is required. * Read-only source code access must be established and maintained under least privilege principles. ## Description The Application Security Senior Consultant serves as the technical authority responsible for conducting expert manual secure code reviews and security assessments of enterprise applications, primarily focusing on large C#/.NET codebases. This role identifies security weaknesses that automated tools may miss and ensures the accuracy and actionability of findings delivered to stakeholders. The consultant leads architecture reviews, assesses multiple security dimensions, prioritizes risks, and provides detailed remediation guidance to enhance the security posture of critical financial and transaction-processing applications. Responsibilities: * Lead architecture walkthroughs with application and development subject matter experts (SMEs). * Establish and validate read-only source code access under least privilege principles. * Create technology and framework inventories for each application assessed. * Develop criticality-weighted coverage plans focusing manual review on business-critical code paths. * Perform manual secure code reviews across architecture, access control, data protection, business logic, and security-sensitive code paths. * Map trust boundaries, data flows, and external system interactions per application. * Construct and test abuse cases against critical business rules and transaction logic. * Trace and verify authorization enforcement workflows and separation of duties. * Assess cryptographic implementations, key lifecycle, and secrets management. * Escalate confirmed high-impact findings within 4 business hours. * Assign CVSS v3.1 base and environmental ratings to findings and agree on environmental context. * Author prescriptive remediation guidance specific to the C#/.NET codebase. * Identify root-cause patterns across applications and contribute to technical and strategic report sections. * Lead technical findings discussions and support report presentations to leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Hacking C# from the inside - how to do anything in NET](https://www.wearedevelopers.com/videos/117-hacking-c-from-the-inside-how-to-do-anything-in-net) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)