Application Security Consultant (SAST & DAST)
Job Summary
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Location:Hyderabad Bengaluru Pune Chennai
Notice Period: 0-30 days
Requirements
We are seeking an experienced Consultant with deep expertise in Application Security Testing to join our growing team. The ideal candidate brings hands-on mastery of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) paired with strong vulnerability triage and remediation-guidance skills. This role requires a technically versatile security engineer who can scan analyze and validate findings across the full application security lifecycle - from source code analysis to runtime testing - while contributing to tool configuration false-positive triage and secure development practices and collaborating effectively with cross-functional teams in a fast-paced consulting environment.
Key Responsibilities
Partner with client and internal teams to gather analyze and translate application security requirements into robust SAST and DAST testing plans.
Configure execute and maintain SAST scans using tools such as Checkmarx or Fortify across enterprise codebases.
Configure execute and maintain DAST scans using tools such as HCL AppScan and Burp Suite against web applications and APIs.
Triage scan findings to distinguish true positives from false positives and provide developers with clear actionable remediation guidance.
Support application onboarding into scan tooling manage scan scheduling and maintain scan coverage across the application portfolio.
Validate remediated vulnerabilities and drive findings through to closure in the Vulnerability Information Tracker or equivalent defect-tracking system.
Collaborate with development DevOps and platform engineering teams to embed security testing within CI/CD pipelines.
Analyze vulnerability trends across OWASP Top 10 categories and recommend systemic fixes to reduce recurring findings.
Document scan configurations triage decisions and remediation guidance clearly and consistently.
Troubleshoot scan failures tool connectivity issues and environment-specific scanning challenges.
Contribute to reusable secure-coding patterns scanning standards and best practices for application security testing.
Support release-gating and production-release security reviews including exception and risk-acceptance workflows.
Mentor junior security analysts and support knowledge transfer across the application security testing team.
Required Skills
SAST & Static Code Analysis
Static Application Security Testing (SAST) Mastery: Proven experience configuring and running static code analysis tools (Checkmarx Fortify SonarQube or equivalent) across multiple languages and frameworks.
Strong understanding of secure coding principles common code-level vulnerability patterns and remediation techniques.
Ability to tune SAST rulesets and scan policies to reduce noise while maintaining detection coverage.
Experience integrating SAST scans into build pipelines and interpreting scan results at scale.
DAST & Dynamic Testing
Dynamic Application Security Testing (DAST) Mastery: Hands-on expertise running dynamic scans against web applications and APIs using tools such as HCL AppScan Burp Suite or OWASP ZAP.
Working knowledge of authenticated scanning session handling and crawling configuration for complex applications.
Familiarity with API security testing including REST and SOAP endpoints and common API-specific vulnerability classes.
Experience validating dynamic findings against application behavior to confirm exploitability.
Vulnerability Management & Triage
Strong grounding in the OWASP Top 10 and related vulnerability taxonomies (Broken Access Control Injection Security Misconfiguration Sensitive Data Exposure and others).
Experience with false-positive analysis and root-cause triage across SAST DAST and software composition analysis (SCA) findings.
Familiarity with Vulnerability Information Tracker (VIT) workflows: creation validation and closure of defects.
Understanding of risk-rating methodologies (CVSS or equivalent) to prioritize remediation effort.
Tooling & Integration
Experience with software composition analysis (SCA) and secret-scanning tools (e.g. Checkmarx SCA Cycode or equivalent).
Familiarity with CI/CD platforms (Azure DevOps GitHub Actions GitLab CI/CD) and embedding security scans within pipelines.
Exposure to cloud security posture and configuration scanning tools (e.g. Prisma Cloud) is a plus.
Basic scripting ability (PowerShell Python or Bash) to support scan automation and reporting.
Collaboration & Communication
Ability to work effectively with cross-functional teams including developers architects DevOps and platform engineering.
Strong problem-solving analytical and written/verbal communication skills.
Ability to document scan findings remediation guidance and risk decisions clearly and concisely.
Experience in client-facing roles with demonstrated ability to present security findings to non-technical stakeholders.
Preferred Qualifications
Experience delivering application security testing services in a consulting or professional services environment.
Familiarity with cloud platforms such as Microsoft Azure AWS or GCP including native security tooling and configuration scanning.
Experience supporting multi-environment deployment processes including development QA UAT and production releases.
Exposure to penetration testing security header validation and automated security testing frameworks.
Understanding of secure SDLC practices enterprise security standards and regulatory compliance considerations (HIPAA PCI-DSS or equivalent).
Experience with agile/scrum delivery methodologies sprint planning and backlog management.
Familiarity with tool-outage support procedures and SOP-based incident response for scanning platforms.
Required Skills:
SAST & Static Code Analysis Static Application Security Testing (SAST) Mastery: Proven experience configuring and running static code analysis tools (Checkmarx Fortify SonarQube or equivalent) across multiple languages and frameworks. Strong understanding of secure coding principles common code-level vulnerability patterns and remediation techniques. Ability to tune SAST rulesets and scan policies to reduce noise while maintaining detection coverage. Experience integrating SAST scans into build pipelines and interpreting scan results at scale. DAST & Dynamic Testing Dynamic Application Security Testing (DAST) Mastery: Hands-on expertise running dynamic scans against web applications and APIs using tools such as HCL AppScan Burp Suite or OWASP ZAP. Working knowledge of authenticated scanning session handling and crawling configuration for complex applications. Familiarity with API security testing including REST and SOAP endpoints and common API-specific vulnerability classes. Experience validating dynamic findings against application behavior to confirm exploitability. Vulnerability Management & Triage Strong grounding in the OWASP Top 10 and related vulnerability taxonomies (Broken Access Control Injection Security Misconfiguration Sensitive Data Exposure and others). Experience with false-positive analysis and root-cause triage across SAST DAST and software composition analysis (SCA) findings. Familiarity with Vulnerability Information Tracker (VIT) workflows: creation validation and closure of defects. Understanding of risk-rating methodologies (CVSS or equivalent) to prioritize remediation effort. Tooling & Integration Experience with software composition analysis (SCA) and secret-scanning tools (e.g. Checkmarx SCA Cycode or equivalent). Familiarity with CI/CD platforms (Azure DevOps GitHub Actions GitLab CI/CD) and embedding security scans within pipelines. Exposure to cloud security posture and configuration scanning tools (e.g. Prisma Cloud) is a plus. Basic scripting ability (PowerShell Python or Bash) to support scan automation and reporting. Collaboration & Communication Ability to work effectively with cross-functional teams including developers architects DevOps and platform engineering. Strong problem-solving analytical and written/verbal communication skills. Ability to document scan findings remediation guidance and risk decisions clearly and concisely. Experience in client-facing roles with demonstrated ability to present security findings to non-technical stakeholders.
Required Education:
Bachelors degree in Computer Science Information Technology or related field.