SASTDAST Application Security Consultant (Pen Testing)
Job Summary
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Experience:3-8 Years
Roles & Responsibilities
As a Senior Consultant SAST/DAST/Penetration Testing the candidate will be responsible for:
- Integrating SAST and DAST security tools into CI/CD pipelines to automate application security testing throughout the development lifecycle.
- Performing regular static and dynamic application security assessments to identify vulnerabilities including SQL Injection Cross-Site Scripting (XSS) and other OWASP Top 10 risks.
- Analyzing security scan results triaging and validating findings and providing actionable remediation guidance to development teams.
- Collaborating with developers to promote secure coding practices and support secure design and application security reviews.
- Defining and maintaining security roles responsibilities and ownership between Deloitte and client stakeholders for security test preparation execution and support.
- Tracking vulnerabilities through their lifecycle and ensuring findings are reported remediated and validated in accordance with organizational policies and client requirements.
- Conducting Root Cause Analysis (RCA) workshops for security findings and recurring vulnerabilities.
- Preparing and publishing security testing reports dashboards and performance metrics.
- Staying current with emerging application security threats industry trends OWASP standards and advancements in SAST/DAST tools and methodologies.
- Hands-on experience with leading SAST and DAST tools including:
- Checkmarx
- Veracode
- Fortify
- Burp Suite
- OWASP ZAP
- Checkmarx
- Strong understanding of Secure Software Development Lifecycle (SSDLC) principles.
- Strong knowledge of OWASP Top 10 vulnerabilities and application security best practices.
- Experience integrating security testing into CI/CD pipelines including Jenkins Azure DevOps and GitLab CI.
- Ability to interpret validate prioritize and communicate vulnerability findings and remediation recommendations to technical and non-technical stakeholders.
- Strong understanding of both white-box (SAST) and black-box (DAST) testing methodologies.
- Practical experience in application security and vulnerability management.
- Bachelors degree or higher in Computer Science Cybersecurity Information Security or a related field or equivalent professional experience.
- Security certifications such as CSSLP CEH or equivalent are preferred.
- Experience with cloud-native application security and container security.
- Knowledge of regulatory and compliance requirements related to application security.
- Experience participating in or conducting Security Architecture Reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
- Proficiency in Threat Modeling methodologies such as STRIDE PASTA or equivalent frameworks.
- Ability to systematically identify document assess and prioritize potential threats and attack vectors.
- Experience translating threat-model findings into actionable SAST/DAST test cases.
- Ability to ensure identified threats are adequately tested remediated and validated.
- Experience with DevSecOps cloud security container security API security and modern application architectures.
Required Skills:
Required Skills Hands-on experience with leading SAST and DAST tools including: Checkmarx Veracode Fortify Burp Suite OWASP ZAP Strong understanding of Secure Software Development Lifecycle (SSDLC) principles. Strong knowledge of OWASP Top 10 vulnerabilities and application security best practices. Experience integrating security testing into CI/CD pipelines including Jenkins Azure DevOps and GitLab CI. Ability to interpret validate prioritize and communicate vulnerability findings and remediation recommendations to technical and non-technical stakeholders. Strong understanding of both white-box (SAST) and black-box (DAST) testing methodologies. Practical experience in application security and vulnerability management. Qualifications Bachelors degree or higher in Computer Science Cybersecurity Information Security or a related field or equivalent professional experience. Security certifications such as CSSLP CEH or equivalent are preferred. Experience with cloud-native application security and container security. Knowledge of regulatory and compliance requirements related to application security. Good to Have Experience participating in or conducting Security Architecture Reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards. Proficiency in Threat Modeling methodologies such as STRIDE PASTA or equivalent frameworks. Ability to systematically identify document assess and prioritize potential threats and attack vectors. Experience translating threat-model findings into actionable SAST/DAST test cases. Ability to ensure identified threats are adequately tested remediated and validated. Experience with DevSecOps cloud security container security API security and modern application architectures.
Required Education:
BE / / MCA / . in Computer Science or equivalent degree from an accredited university.