> Markdown version of [/jobs/ext/608322-security-consultant](https://www.wearedevelopers.com/jobs/ext/608322-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Consultant - **Company:** High Bridge Consulting - **Location:** Parsippany, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Adobe InDesign, Amazon Web Services, Amazon S3, Software System Penetration Testing, Cloud Computing Security, Code Review, Continuous Integration, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Node.Js, Open Web Application Security, Release Management, Secure Coding, Software Deployment, Software Security, AWS Lambda, Cyber Threat Analysis, Checkmarx, Api Gateway, Prisma Cloud Platform, Devsecops, Static Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://www.dice.com/job-detail/ecacb745-f202-45aa-be7a-cc6883a57f71 ## About the Role * 3+ years in application security (offense and defense) with hands-on SAST/SCA experience. * Strong knowledge of OWASP Top Ten and web/API security vulnerabilities and remediation. * Experience securing AWS cloud services and working with cloud security platforms (e.g., Wiz, Prisma Cloud, Orca). * Ability to read and review code in Java, JavaScript/Node.js, or Python for security validation. * Experience with CI/CD pipelines, DevSecOps practices, and secure SDLC integration. * Strong communication skills with ability to influence technical and business stakeholders. * Experience working with change/release management in production environments., * Familiarity with threat intelligence and how it informs application security controls. * Experience driving developer security adoption through workshops or working sessions. * Strong understanding of agile delivery environments and enterprise release governance. ## Description * Lead application security design across web, mobile, and AWS cloud-native systems, including secure architecture reviews and CI/CD security integration. * Administer and optimize SAST/SCA tools (e.g., Checkmarx, Snyk), triage vulnerabilities, and guide remediation aligned to OWASP Top Ten. * Secure cloud environments (especially AWS Lambda, API Gateway, IAM, S3) and support runtime and application-layer protections. * Partner with release and change management to ensure secure, stable production deployments and support go-live readiness. * Provide security input in architecture and project planning, ensuring requirements are embedded early in design and development. * Track vulnerabilities, produce reporting, and manage remediation progress across engineering teams., * Automate security testing and improve security tooling workflows. * Develop and improve security runbooks, documentation, and operational procedures. * Support penetration testing, secure code reviews, or developer training as needed. * Participate in additional architecture discussions or advisory meetings when required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)