> Markdown version of [/jobs/ext/2721796-senior-application-security-consultant](https://www.wearedevelopers.com/jobs/ext/2721796-senior-application-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Consultant - **Company:** Talent Groups - **Location:** Mountain Lakes, NJ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Amazon S3, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Identity and Access Management, Python (Programming Language), Node.Js, Open Web Application Security, Release Management, Secure Coding, Software Vulnerability Management, Enterprise Software Applications, Cloud Platform System, Spring Cloud, Software Security, Checkmarx, Functional Programming, Api Gateway, Prisma Cloud Platform, Devsecops, Static Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://www.disabledperson.com/jobs/74873018-senior-application-security-consultant ## About the Role * 3+ years of recent, hands-on Application Security experience. * Strong experience with SAST/SCA, particularly Checkmarx and Snyk. * Strong knowledge of OWASP Top 10, web/API vulnerabilities, and remediation techniques. * Hands-on AWS security experience with Lambda, API Gateway, IAM, and S3. * Experience with Wiz, Orca Security, or Prisma Cloud. * Ability to read and understand code in JavaScript, Node.js, Java, or Python. * Experience with secure code review, vulnerability triage, DevSecOps, CI/CD, and Agile. * Experience working with development teams and production release/change management. * Strong communication and stakeholder-management skills. Ideal Candidate The strongest candidates will have current AppSec experience, hands-on knowledge of modern security tools and cloud environments, and the ability to understand code and work directly with developers on remediation. Important: Candidates must be able to work onsite Tuesday-Thursday in Parsippany, NJ. ## Description Our client is seeking a hands-on Application Security Consultant to support and mature its enterprise application security program. The ideal candidate will have recent AppSec experience across secure development, SAST/SCA, vulnerability management, AWS security, secure code review, and DevSecOps. The consultant will work closely with development, cloud engineering, cybersecurity, and business teams to identify security risks, support remediation, and ensure applications are securely designed, developed, and deployed., * Lead application security reviews across web, mobile, API, and cloud-native applications. * Administer and optimize Checkmarx and Snyk, including scanning, ruleset tuning, findings triage, and remediation tracking. * Apply OWASP Top 10 principles to identify and remediate application and API vulnerabilities. * Perform secure code review and validate findings using JavaScript, Node.js, Java, or Python. * Secure AWS environments, including Lambda, API Gateway, IAM, and S3. * Work with cloud security platforms such as Wiz, Orca Security, or Prisma Cloud. * Integrate security controls into CI/CD and DevSecOps pipelines. * Support application-layer protection, production releases, change management, and go-live activities. * Partner with developers and engineering teams to drive vulnerability remediation and secure coding practices. * Represent Application Security in architecture, project planning, and risk discussions. * Prepare security reports and track remediation activities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)