Senior Application Security Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+15 more
Job description
Our client is seeking a hands-on Application Security Consultant to support and mature its enterprise application security program. The ideal candidate will have recent AppSec experience across secure development, SAST/SCA, vulnerability management, AWS security, secure code review, and DevSecOps.
The consultant will work closely with development, cloud engineering, cybersecurity, and business teams to identify security risks, support remediation, and ensure applications are securely designed, developed, and deployed., * Lead application security reviews across web, mobile, API, and cloud-native applications.
- Administer and optimize Checkmarx and Snyk, including scanning, ruleset tuning, findings triage, and remediation tracking.
- Apply OWASP Top 10 principles to identify and remediate application and API vulnerabilities.
- Perform secure code review and validate findings using JavaScript, Node.js, Java, or Python.
- Secure AWS environments, including Lambda, API Gateway, IAM, and S3.
- Work with cloud security platforms such as Wiz, Orca Security, or Prisma Cloud.
- Integrate security controls into CI/CD and DevSecOps pipelines.
- Support application-layer protection, production releases, change management, and go-live activities.
- Partner with developers and engineering teams to drive vulnerability remediation and secure coding practices.
- Represent Application Security in architecture, project planning, and risk discussions.
- Prepare security reports and track remediation activities.
Requirements
- 3+ years of recent, hands-on Application Security experience.
- Strong experience with SAST/SCA, particularly Checkmarx and Snyk.
- Strong knowledge of OWASP Top 10, web/API vulnerabilities, and remediation techniques.
- Hands-on AWS security experience with Lambda, API Gateway, IAM, and S3.
- Experience with Wiz, Orca Security, or Prisma Cloud.
- Ability to read and understand code in JavaScript, Node.js, Java, or Python.
- Experience with secure code review, vulnerability triage, DevSecOps, CI/CD, and Agile.
- Experience working with development teams and production release/change management.
- Strong communication and stakeholder-management skills.
Ideal Candidate
The strongest candidates will have current AppSec experience, hands-on knowledge of modern security tools and cloud environments, and the ability to understand code and work directly with developers on remediation.
Important: Candidates must be able to work onsite Tuesday-Thursday in Parsippany, NJ.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Is Software Engineering Over-Saturated?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Find a Developer Job: 12 Best Job Sites For Developers
Fully Remote Software Engineer Jobs