Alignity Solutions

Application Security Consultant (SAST & DAST)

Alignity Solutions · Hyderabad, Telangana, India

IT Services and IT Consulting · 11-50 employees

20 h ago
Senior (5-10 yrs) Contractor India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The consultant will configure and execute SAST and DAST scans while providing actionable remediation guidance to development teams. They will also collaborate with DevOps to integrate security testing into CI/CD pipelines and manage vulnerability tracking through to closure.

What they look for

SAST DAST Checkmarx Fortify HCL AppScan Burp Suite Vulnerability Triage Remediation Guidance CI/CD Pipelines OWASP Top 10 API Security Python Bash PowerShell SCA Secure Coding

Requirements

The ideal candidate possesses 5-8 years of experience with deep expertise in static and dynamic application security testing tools. Strong analytical skills for vulnerability triage and the ability to communicate effectively with cross-functional teams are essential.

Full description

Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.

Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees.

  • Jobseeker Video Testimonials
  • Employee Glassdoor Reviews

If you are a Application Security Consultant​ looking for excitement, challenge and stability in your work, then you would be glad to come across this page.

We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.

Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.

Role:Application Security Consultant

Experience:5-8Years Location:Hyderabad | Bengaluru | Pune | Chennai

Work Mode:Hybrid

Type:Contract to Hire Notice Period: 0-30 days

Requirements

We are seeking an experienced Consultant with deep expertise in Application Security Testing to join our growing team. The ideal candidate brings hands-on mastery of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), paired with strong vulnerability triage and remediation-guidance skills. This role requires a technically versatile security engineer who can scan, analyze, and validate findings across the full application security lifecycle - from source code analysis to runtime testing - while contributing to tool configuration, false-positive triage, and secure development practices, and collaborating effectively with cross-functional teams in a fast-paced consulting environment.

Key Responsibilities

  • Partner with client and internal teams to

gather, analyze, and translate application security requirements into robust SAST and DAST testing plans.

  • Configure, execute, and maintain SAST scans

using tools such as Checkmarx or Fortify across enterprise codebases.

  • Configure, execute, and maintain DAST scans

using tools such as HCL AppScan and Burp Suite, against web applications and APIs.

  • Triage scan findings to distinguish true

positives from false positives, and provide developers with clear, actionable remediation guidance.

  • Support application onboarding into scan

tooling, manage scan scheduling, and maintain scan coverage across the application portfolio.

  • Validate remediated vulnerabilities and drive

findings through to closure in the Vulnerability Information Tracker or equivalent defect-tracking system.

  • Collaborate with development, DevOps, and

platform engineering teams to embed security testing within CI/CD pipelines.

  • Analyze vulnerability trends across OWASP Top 10

categories and recommend systemic fixes to reduce recurring findings.

  • Document scan configurations, triage decisions,

and remediation guidance clearly and consistently.

  • Troubleshoot scan failures, tool connectivity

issues, and environment-specific scanning challenges.

  • Contribute to reusable secure-coding patterns,

scanning standards, and best practices for application security testing.

  • Support release-gating and production-release

security reviews, including exception and risk-acceptance workflows.

  • Mentor junior security analysts and support

knowledge transfer across the application security testing team.

Required Skills

SAST & Static Code Analysis

  • Static Application Security Testing (SAST) —

Mastery: Proven experience configuring and running static code analysis tools (Checkmarx, Fortify, SonarQube, or equivalent) across multiple languages and frameworks.

  • Strong understanding of secure coding

principles, common code-level vulnerability patterns, and remediation techniques.

  • Ability to tune SAST rulesets and scan policies

to reduce noise while maintaining detection coverage.

  • Experience integrating SAST scans into build

pipelines and interpreting scan results at scale.

DAST & Dynamic Testing

  • Dynamic Application Security Testing (DAST) —

Mastery: Hands-on expertise running dynamic scans against web applications and APIs using tools such as HCL AppScan, Burp Suite, or OWASP ZAP.

  • Working knowledge of authenticated scanning,

session handling, and crawling configuration for complex applications.

  • Familiarity with API security testing, including

REST and SOAP endpoints, and common API-specific vulnerability classes.

  • Experience validating dynamic findings against

application behavior to confirm exploitability.

Vulnerability Management & Triage

  • Strong grounding in the OWASP Top 10 and related

vulnerability taxonomies (Broken Access Control, Injection, Security Misconfiguration, Sensitive Data Exposure, and others).

  • Experience with false-positive analysis and

root-cause triage across SAST, DAST, and software composition analysis (SCA) findings.

  • Familiarity with Vulnerability Information

Tracker (VIT) workflows: creation, validation, and closure of defects.

  • Understanding of risk-rating methodologies (CVSS

or equivalent) to prioritize remediation effort.

Tooling & Integration

  • Experience with software composition analysis

(SCA) and secret-scanning tools (e.g., Checkmarx SCA, Cycode, or equivalent).

  • Familiarity with CI/CD platforms (Azure DevOps,

GitHub Actions, GitLab CI/CD) and embedding security scans within pipelines.

  • Exposure to cloud security posture and

configuration scanning tools (e.g., Prisma Cloud) is a plus.

  • Basic scripting ability (PowerShell, Python, or

Bash) to support scan automation and reporting.

Collaboration & Communication

  • Ability to work effectively with

cross-functional teams including developers, architects, DevOps, and platform engineering.

  • Strong problem-solving, analytical, and

written/verbal communication skills.

  • Ability to document scan findings, remediation

guidance, and risk decisions clearly and concisely.

  • Experience in client-facing roles with

demonstrated ability to present security findings to non-technical stakeholders.

Preferred Qualifications

  • Experience delivering application security

testing services in a consulting or professional services environment.

  • Familiarity with cloud platforms such as

Microsoft Azure, AWS, or GCP, including native security tooling and configuration scanning.

  • Experience supporting multi-environment

deployment processes including development, QA, UAT, and production releases.

  • Exposure to penetration testing, security header

validation, and automated security testing frameworks.

  • Understanding of secure SDLC practices,

enterprise security standards, and regulatory compliance considerations (HIPAA, PCI-DSS, or equivalent).

  • Experience with agile/scrum delivery

methodologies, sprint planning, and backlog management.

  • Familiarity with tool-outage support procedures

and SOP-based incident response for scanning platforms.