SAST/DAST Application Security Consultant (Pen Testing)
Alignity Solutions Hyderabad, Telangana, India · ₹2M/yr
IT Services and IT Consulting · 11-50 employees
About the role
The consultant will integrate SAST and DAST security tools into CI/CD pipelines to automate testing throughout the development lifecycle. They will also perform regular security assessments, triage vulnerabilities, and provide actionable remediation guidance to development teams.
What they look for
Requirements
Candidates must have 3-8 years of experience with leading SAST/DAST tools and a strong understanding of OWASP Top 10 vulnerabilities. A bachelor's degree in a relevant field is required, with professional security certifications preferred.
Full description
Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.
Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees.
- Jobseeker Video Testimonials
- Employee Glassdoor Reviews
If you are a SAST/DAST Application Security Consultant looking for excitement, challenge and stability in your work, then you would be glad to come across this page.
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.
Role:SAST/DAST Application Security Consultant - Penetration Testing
Location: Hyderabad Experience:3-8 Years
Work Mode: Hybrid
Type: Contract to Hire
Notice Period:Immediate Joiners
Requirements
Roles & Responsibilities
As a Senior Consultant – SAST/DAST/Penetration Testing, the candidate will be responsible for:
- Integrating SAST and DAST security tools into CI/CD pipelines to automate application security testing throughout the development lifecycle.
- Performing regular static and dynamic application security assessments to identify vulnerabilities, including SQL Injection, Cross-Site Scripting (XSS), and other OWASP Top 10 risks.
- Analyzing security scan results, triaging and validating findings, and providing actionable remediation guidance to development teams.
- Collaborating with developers to promote secure coding practices and support secure design and application security reviews.
- Defining and maintaining security roles, responsibilities, and ownership between Deloitte and client stakeholders for security test preparation, execution, and support.
- Tracking vulnerabilities through their lifecycle and ensuring findings are reported, remediated, and validated in accordance with organizational policies and client requirements.
- Conducting Root Cause Analysis (RCA) workshops for security findings and recurring vulnerabilities.
- Preparing and publishing security testing reports, dashboards, and performance metrics.
- Staying current with emerging application security threats, industry trends, OWASP standards, and advancements in SAST/DAST tools and methodologies.
Required Skills
- Hands-on experience with leading SAST and DAST tools, including:
- Checkmarx
- Veracode
- Fortify
- Burp Suite
- OWASP ZAP
- Strong understanding of Secure Software Development Lifecycle (SSDLC) principles.
- Strong knowledge of OWASP Top 10 vulnerabilities and application security best practices.
- Experience integrating security testing into CI/CD pipelines, including Jenkins, Azure DevOps, and GitLab CI.
- Ability to interpret, validate, prioritize, and communicate vulnerability findings and remediation recommendations to technical and non-technical stakeholders.
- Strong understanding of both white-box (SAST) and black-box (DAST) testing methodologies.
- Practical experience in application security and vulnerability management.
Qualifications
- Bachelor's degree or higher in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent professional experience.
- Security certifications such as CSSLP, CEH, or equivalent are preferred.
- Experience with cloud-native application security and container security.
- Knowledge of regulatory and compliance requirements related to application security.
Good to Have
- Experience participating in or conducting Security Architecture Reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
- Proficiency in Threat Modeling methodologies such as STRIDE, PASTA, or equivalent frameworks.
- Ability to systematically identify, document, assess, and prioritize potential threats and attack vectors.
- Experience translating threat-model findings into actionable SAST/DAST test cases.
- Ability to ensure identified threats are adequately tested, remediated, and validated.
- Experience with DevSecOps, cloud security, container security, API security, and modern application architectures.
Benefits
Visit us at http://alignity.io/careers. Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.
CEO Message: Click Here
Clients Testimonial: Click Here
Similar roles
-
Senior Security Engineer (m/w/d)
Yoummday GmbH Sofia, Sofia-City, Bulgaria
-
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response
Xplor Atlanta, Georgia, United States
-
Principal Cloud Security Engineer
LastPass Canada
-
Senior Network Security Engineer (m/f/d)
We One Łódź, Łódź Voivodeship, Poland · PLN 92K–PLN 146K/yr
-
Data Privacy and Protection - Cyber GRC Professional - Cybersecurity
EY Greece Patras, Peloponnese, Western Greece and the Ionian, Greece
- Italian Speaking Cybersecurity Customer Experts - Work In Athens, Greece