Senior Application Security Consultant

Talent Groups
Denville, NJ, United States
2 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Amazon S3 Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration Identity and Access Management Python (Programming Language)
+15 more
Node.Js Open Web Application Security Release Management Secure Coding Software Vulnerability Management Enterprise Software Applications Cloud Platform System Spring Cloud Software Security Checkmarx Functional Programming Api Gateway Prisma Cloud Platform Devsecops Static Application Security Testing

Job description

Our client is seeking a hands-on Application Security Consultant to support and mature its enterprise application security program. The ideal candidate will have recent AppSec experience across secure development, SAST/SCA, vulnerability management, AWS security, secure code review, and DevSecOps.

The consultant will work closely with development, cloud engineering, cybersecurity, and business teams to identify security risks, support remediation, and ensure applications are securely designed, developed, and deployed., * Lead application security reviews across web, mobile, API, and cloud-native applications.

  • Administer and optimize Checkmarx and Snyk, including scanning, ruleset tuning, findings triage, and remediation tracking.
  • Apply OWASP Top 10 principles to identify and remediate application and API vulnerabilities.
  • Perform secure code review and validate findings using JavaScript, Node.js, Java, or Python.
  • Secure AWS environments, including Lambda, API Gateway, IAM, and S3.
  • Work with cloud security platforms such as Wiz, Orca Security, or Prisma Cloud.
  • Integrate security controls into CI/CD and DevSecOps pipelines.
  • Support application-layer protection, production releases, change management, and go-live activities.
  • Partner with developers and engineering teams to drive vulnerability remediation and secure coding practices.
  • Represent Application Security in architecture, project planning, and risk discussions.
  • Prepare security reports and track remediation activities.

Requirements

  • 3+ years of recent, hands-on Application Security experience.
  • Strong experience with SAST/SCA, particularly Checkmarx and Snyk.
  • Strong knowledge of OWASP Top 10, web/API vulnerabilities, and remediation techniques.
  • Hands-on AWS security experience with Lambda, API Gateway, IAM, and S3.
  • Experience with Wiz, Orca Security, or Prisma Cloud.
  • Ability to read and understand code in JavaScript, Node.js, Java, or Python.
  • Experience with secure code review, vulnerability triage, DevSecOps, CI/CD, and Agile.
  • Experience working with development teams and production release/change management.
  • Strong communication and stakeholder-management skills.

Ideal Candidate

The strongest candidates will have current AppSec experience, hands-on knowledge of modern security tools and cloud environments, and the ability to understand code and work directly with developers on remediation.

Important: Candidates must be able to work onsite Tuesday-Thursday in Parsippany, NJ.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · World Congress 2023

Videos

See all

Related articles

See all