HamburgerMenu
hirist

Job Description

Role Overview :

We are looking for an experienced Source Code Review Consultant with strong expertise in Application Security to identify, assess, and remediate security vulnerabilities within software applications. The ideal candidate should have hands-on experience in secure code reviews, SAST tools, vulnerability assessments, secure development practices, and integrating security into SDLC and CI/CD pipelines. This role requires strong technical acumen, analytical thinking, and effective stakeholder communication skills.

Job Title : Source Code Review Consultant (Application Security)

Experience : 6+ Years

Employment Type : Full Time, Permanent

Department : IT & Information Security

Role Category : IT & Information Security Other

Education : UG : Any Graduate (Preferred in Computer Science, IT, Cybersecurity, or related field)

Key Responsibilities :

- Perform secure source code reviews for web, mobile, and enterprise applications across multiple programming languages.

- Identify security vulnerabilities, coding flaws, and architectural weaknesses in applications.

- Conduct static application security testing (SAST) using industry-standard tools.

- Analyze vulnerabilities such as SQL Injection, XSS, CSRF, SSRF, RCE, insecure deserialization, authentication bypass, and privilege escalation issues.

- Provide detailed remediation recommendations and secure coding guidance to development teams.

- Validate fixes and ensure vulnerabilities are remediated effectively.

- Conduct threat modeling and security risk assessments during application design and development phases.

- Collaborate with developers, DevOps, QA, and security teams to improve application security posture.

- Integrate security testing into CI/CD pipelines to enable continuous security validation.

- Ensure adherence to secure coding standards including OWASP Top 10, SANS, and industry best practices.

- Support security audits, compliance assessments, and penetration testing initiatives.

- Create technical reports, dashboards, and presentations for technical and business stakeholders.

- Mentor engineering teams on secure coding principles and security best practices.

Key Responsibility Areas (KRA) :

- Secure source code review and vulnerability identification.

- Static Application Security Testing (SAST) implementation and analysis.

- Vulnerability assessment, risk classification, and remediation guidance.

- Threat modeling and secure architecture reviews.

- CI/CD security integration and DevSecOps enablement.

- Security standards compliance and governance.

- Stakeholder communication and security advisory support.

- Secure SDLC implementation and continuous improvement.

Required Skillsets :

- Strong expertise in secure code review methodologies.

- Hands-on experience with SAST tools such as Checkmarx, Fortify, Veracode, SonarQube, or similar.

- Deep understanding of application security vulnerabilities and attack vectors.

- Strong knowledge of OWASP Top 10, CWE/SANS Top 25, and secure coding standards.

- Experience in threat modeling methodologies such as STRIDE or DREAD.

- Strong understanding of SDLC, DevSecOps, and CI/CD security practices.

- Proficiency in programming languages such as Java, Python, C#, JavaScript, Node.js, or Go.

- Knowledge of secure API design and API security testing.

- Familiarity with cloud security concepts across AWS, Azure, or GCP.

- Experience with vulnerability management and risk prioritization.

- Strong analytical, troubleshooting, and problem-solving skills.

- Excellent communication and stakeholder management skills.

Preferred Skills :

- Certifications such as CEH, CSSLP, OSCP, CISSP, GWAPT, or equivalent.

- Experience in penetration testing and dynamic application security testing (DAST).

- Exposure to container security, Kubernetes security, and cloud-native security.

- Familiarity with compliance standards such as ISO 27001, PCI-DSS, SOC 2, or GDPR.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...