Tech Summary
The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance.
The ideal candidate has advanced software development and application security experience using Java, Python, JavaScript, .NET, Swift, or similar technologies. The candidate should have practical experience with application security testing solutions, penetration testing tools such as Burp Suite or OWASP ZAP, and integrating security controls into CI/CD pipelines.
This role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations. Experience with cloud native applications, APIs, mobile applications, AI enabled applications, DevSecOps automation, and healthcare or other regulated environments is preferred.
Job Summary:In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.
Auto-detected from this job's description. Click any skill to find similar roles.
Join thousands of professionals finding verified U.S. jobs every day. Sign up free, set your preferences, and let opportunities come to you.