← Back to jobs

CareerNet Technologies Pvt Ltd Logo
SAST/DAST Application Security Consultant

CareerNet Technologies Pvt Ltd

 

Chennai, Tamil Nadu, India

Posted On: 15+ days ago
Experience: 7+ years
Availability: Onsite
Openings: 1
Category: Application Security Consultant
Tenure: No Preference/Any
Related Jobs

No related jobs found

Description

Key Skills: Application Security Testing, DAST, Pipeline, Software Development

Roles and Responsibilities:

  • Integrate SAST and DAST tools into CI/CD pipelines to automate security testing throughout the development lifecycle.
  • Perform regular static (SAST) and dynamic (DAST) security assessments on applications to identify vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.
  • Analyze scan results, triage findings, and provide actionable remediation guidance to development teams.
  • Collaborate with developers to ensure secure coding practices and support secure design reviews.
  • Define and maintain security roles, responsibilities, and ownership between Deloitte and client stakeholders for test preparation, execution, and support.
  • Ensure that vulnerabilities are tracked, reported, and resolved in accordance with organizational policies and client requirements.
  • Conduct root cause analysis (RCA) workshops and publish performance and security testing reports.
  • Stay current with industry trends, emerging threats, and advancements in SAST/DAST tools and methodologies.

Skills Required:

  • Security certifications such as CSSLP, CEH, or similar certifications are preferred.
  • Hands-on experience with leading SAST and DAST tools such as Checkmarx, Veracode, Fortify, Burp Suite, and OWASP ZAP.
  • Strong understanding of Secure Software Development Lifecycle (SSDLC) principles and OWASP Top 10 vulnerabilities.
  • Experience integrating security testing into CI/CD pipelines such as Jenkins, Azure DevOps, and GitLab CI.
  • Ability to interpret and communicate vulnerability findings and remediation steps to technical and non-technical stakeholders.
  • Familiarity with both black-box (DAST) and white-box (SAST) testing methodologies.
  • Experience with cloud-native application security and container security.
  • Knowledge of regulatory and compliance requirements related to application security.

Good to Have

  • Experience participating in or conducting security architecture reviews to identify design-level vulnerabilities and ensure alignment with security best practices and organizational standards.
  • Proficiency in performing threat modeling exercises using frameworks such as STRIDE, PASTA, or other relevant methodologies to systematically identify, document, and prioritize potential threats and attack vectors in applications and systems.
  • Skill in translating threat model findings into actionable SAST/DAST test cases and ensuring that identified threats are adequately tested and mitigated.

Education : Bachelor's degree or higher in Computer Science, Information Technology, Cybersecurity, or equivalent experience

Education

Any Graduate

Related Jobs

No related jobs found

← Back to jobs