SAST/DAST Application Security Consultant (Pen Testing)
NewBe an early applicantSummary
Contract-to-hire senior application security consultant role in Hyderabad (hybrid): integrating SAST/DAST tools like Checkmarx, Veracode, Fortify, Burp Suite, and OWASP ZAP into CI/CD pipelines, performing penetration tests, triaging findings, and guiding remediation and secure coding practices for a Deloitte client engagement.
- Jobseeker Video Testimonials
- Employee Glassdoor Reviews
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Experience:3-8 Years
Requirements
Roles & Responsibilities
As a Senior Consultant – SAST/DAST/Penetration Testing, the candidate will be responsible for:
- Integrating SAST and DAST security tools into CI/CD pipelines to automate application security testing throughout the development lifecycle.
- Performing regular static and dynamic application security assessments to identify vulnerabilities, including SQL Injection, Cross-Site Scripting (XSS), and other OWASP Top 10 risks.
- Analyzing security scan results, triaging and validating findings, and providing actionable remediation guidance to development teams.
- Collaborating with developers to promote secure coding practices and support secure design and application security reviews.
- Defining and maintaining security roles, responsibilities, and ownership between Deloitte and client stakeholders for security test preparation, execution, and support.
- Tracking vulnerabilities through their lifecycle and ensuring findings are reported, remediated, and validated in accordance with organizational policies and client requirements.
- Conducting Root Cause Analysis (RCA) workshops for security findings and recurring vulnerabilities.
- Preparing and publishing security testing reports, dashboards, and performance metrics.
- Staying current with emerging application security threats, industry trends, OWASP standards, and advancements in SAST/DAST tools and methodologies.
Required Skills
- Hands-on experience with leading SAST and DAST tools, including:
- Checkmarx
- Veracode
- Fortify
- Burp Suite
- OWASP ZAP
- Checkmarx
- Strong understanding of Secure Software Development Lifecycle (SSDLC) principles.
- Strong knowledge of OWASP Top 10 vulnerabilities and application security best practices.
- Experience integrating security testing into CI/CD pipelines, including Jenkins, Azure DevOps, and GitLab CI.
- Ability to interpret, validate, prioritize, and communicate vulnerability findings and remediation recommendations to technical and non-technical stakeholders.
- Strong understanding of both white-box (SAST) and black-box (DAST) testing methodologies.
- Practical experience in application security and vulnerability management.
Qualifications
- Bachelor's degree or higher in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent professional experience.
- Security certifications such as CSSLP, CEH, or equivalent are preferred.
- Experience with cloud-native application security and container security.
- Knowledge of regulatory and compliance requirements related to application security.
Good to Have
- Experience participating in or conducting Security Architecture Reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
- Proficiency in Threat Modeling methodologies such as STRIDE, PASTA, or equivalent frameworks.
- Ability to systematically identify, document, assess, and prioritize potential threats and attack vectors.
- Experience translating threat-model findings into actionable SAST/DAST test cases.
- Ability to ensure identified threats are adequately tested, remediated, and validated.
- Experience with DevSecOps, cloud security, container security, API security, and modern application architectures.
