Security Consultant

High Bridge Consulting
Parsippany, United States
about 2 months ago
Apply on dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Adobe InDesign Amazon Web Services Amazon S3 Software System Penetration Testing Cloud Computing Security Code Review Continuous Integration Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language)
+13 more
Node.Js Open Web Application Security Release Management Secure Coding Software Deployment Software Security AWS Lambda Cyber Threat Analysis Checkmarx Api Gateway Prisma Cloud Platform Devsecops Static Application Security Testing

Job description

  • Lead application security design across web, mobile, and AWS cloud-native systems, including secure architecture reviews and CI/CD security integration.
  • Administer and optimize SAST/SCA tools (e.g., Checkmarx, Snyk), triage vulnerabilities, and guide remediation aligned to OWASP Top Ten.
  • Secure cloud environments (especially AWS Lambda, API Gateway, IAM, S3) and support runtime and application-layer protections.
  • Partner with release and change management to ensure secure, stable production deployments and support go-live readiness.
  • Provide security input in architecture and project planning, ensuring requirements are embedded early in design and development.
  • Track vulnerabilities, produce reporting, and manage remediation progress across engineering teams., * Automate security testing and improve security tooling workflows.
  • Develop and improve security runbooks, documentation, and operational procedures.
  • Support penetration testing, secure code reviews, or developer training as needed.
  • Participate in additional architecture discussions or advisory meetings when required.

Requirements

  • 3+ years in application security (offense and defense) with hands-on SAST/SCA experience.
  • Strong knowledge of OWASP Top Ten and web/API security vulnerabilities and remediation.
  • Experience securing AWS cloud services and working with cloud security platforms (e.g., Wiz, Prisma Cloud, Orca).
  • Ability to read and review code in Java, JavaScript/Node.js, or Python for security validation.
  • Experience with CI/CD pipelines, DevSecOps practices, and secure SDLC integration.
  • Strong communication skills with ability to influence technical and business stakeholders.
  • Experience working with change/release management in production environments., * Familiarity with threat intelligence and how it informs application security controls.
  • Experience driving developer security adoption through workshops or working sessions.
  • Strong understanding of agile delivery environments and enterprise release governance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · World Congress 2023

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all