- Company Name
- Approach Cyber
- Job Title
- Application Security Consultant
- Job Description
-
Job Title: Application Security Consultant
Role Summary:
Senior consultant delivering secure software design and development services, acting as a security champion for client teams. Drives adoption of Secure SDLC, integrates application security tools, mentors internal staff, and contributes to product, presales, and technology watch activities.
Expectations:
- 5‑6+ years of application security experience across multiple tech stacks (C#, .NET, Java, Spring, Angular).
- Hands‑on proficiency with SAST/DAST/SCA (Fortify, Sonarqube, etc.), CVE tracking, and DevSecOps pipelines.
- Strong guidance on OWASP ASVS, security requirements, and security testing before production.
- Ability to mentor junior staff, support dev‑ops tasks, and contribute to Solution Owner responsibilities.
Key Responsibilities:
- Operationalize Security‑by‑Design principles (availability, integrity, confidentiality, traceability).
- Design and implement Secure SDLC/DevSecOps practices for client teams.
- Integrate security tools and processes (SAST, DAST, SCA, CVE follow‑up).
- Define and verify security requirements and test scenarios for production readiness.
- Conduct app‑security assessments, including SAMM assessments and vulnerability remediation.
- Mentor team members on application security projects and complex technical issues.
- Support development and DevOps activities, providing technology guidance for .NET, Angular, Java/Spring, Azure, Azure DevOps, OAuth (KeyCloak).
- Perform technology watch, stay current with emerging tools, and share knowledge internally.
- Act as key representative at security conferences and associations.
- Develop and enhance security assets, methodologies, and documentation.
- Participate in presales meetings, help define customer needs, and support sales enablement.
Required Skills:
- Secure SDLC, DevSecOps, OWASP ASVS, Secure‑by‑Design architecture.
- SAST, DAST, SCA tools (Fortify, Sonarqube, Veracode, etc.).
- Vulnerability management, CVE tracking, remediations.
- Programming familiarity with C#, .NET, Java, Spring, JavaScript, Angular.
- Cloud platforms: Azure, Azure DevOps.
- Security protocols: OAuth, KeyCloak, JWT, TLS.
- Mentoring, coaching, technical leadership.
- Strong written and verbal communication, presentation skills.
Required Education & Certifications:
- Bachelor’s (or higher) degree in Computer Science, Software Engineering, or related field.
- Relevant certifications: CSSLP, CEH, OSCP, CISSP, CISA, or equivalent application‑security credentials preferred.