IBM logo
Company Name:
Approximate Salary:
Not Specified
Position type:
Full Time
Experience level:
2 - 5 years
Education level:
Master's Degree
Sandy Springs
Job Title:
Senior Security Consultant- Application Security

Senior Security Consultant- Application Security

Job Description
*Job Description The successful candidate will perform application security assessments, code reviews, and Software Development Life Cycle (SDLC) security consulting in a customer environment. The candidate will be responsible for identifying specific and systemic security issues within applications and the application development and lifecycle maintenance process, and will also be a resource for the client in establishing and expanding the base of client knowledge in the area of application security.
Projects may include:
•Performing application vulnerability and security assessments
•Performing application security risk assessments
•Performing code review across a variety of programming languages
•Performing assessments of SDLC processes
•Developing testing scripts and procedures
•Developing and delivering application security training and outreach
•Creating gap analysis and client improvement program recommendations
•Other security-related projects that may be assigned according to skills

Candidates must have demonstrated experience in successfully completing tasks and delivering professionally written reports for clients. Must have the ability to present findings to technical staff and executives.

A successful candidate will likely possess some or all of these qualifications as well:
•Experience with web application development (e.g., ASP.NET, ASP, PHP, J2EE, JSP) •Application security experience with high level programming languages (e.g., Java, C, C++, .NET (C#, VB))
•Experience leading software development projects
•Experience with threat modeling and security risk assessment
•Experience with vulnerability scanning tools (e.g., Qualys, Nessus, Nexpose, Saint)
•Experience with web application vulnerability scanning tools (e.g., IBM AppScan, HP, Webinspect, Accunetix, NTO Spider, Burpsuite Pro)
•Experience with static analysis tools (e.g., IBM Appscan Source, HP Fortify) •Familiarity with interactive and automated penetration testing

Required Technical and Professional Expertise

Experience in Application Security
Experience in IT and / or software development
Basic knowledge in common application code review methods and standards
Basic knowledge in application development and coding in modern languages
Basic knowledge in OWASP tools and methodologies
Basic knowledge in and understanding of HTTP and web programming
Basic knowledge in common enabling application security requirements
Basic knowledge in standard Software Development Life Cycle (SDLC) practices
Readiness to travel 75% travel annually
English: Fluent

Preferred Tech and Prof Experience

Bachelor's Degree in Information Technology
Experience in Application Security
Experience in IT and / or software development
Certified in CISSP, CEH, and/or CSSLP

EO Statement
IBM is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.

Apply for this job


More Jobs Like This

Friends Who Might Be Interested