More jobs:
Cybersecurity Consultant IV, Application Security (Greensboro, NC)
Job in
Greensboro, Guilford County, North Carolina, 27497, USA
Listed on 2026-08-14
Listing for:
Kaiser Permanente
Full Time
position Listed on 2026-08-14
Job specializations:
-
IT/Tech
Cybersecurity, IT Consultant
Job Description & How to Apply Below
The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance.
The ideal candidate has advanced software development and application security experience using Java, Python, JavaScript, .NET, Swift, or similar technologies. The candidate should have practical experience with application security testing solutions, penetration testing tools such as Burp Suite or OWASP ZAP, and integrating security controls into CI/CD pipelines.
This role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations.
Experience with cloud native applications, APIs, mobile applications, AI enabled applications, Dev Sec Ops automation, and healthcare or other regulated environments is preferred.
Job Summary:
In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with Dev Ops teams to integrate application security services; training Dev Ops personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans;
and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.
Essential Responsibilities:
- Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities.
- Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses;
supporting team collaboration; and adapting to and learning from change, difficulties, and feedback. - Effectively communicates investigative findings to non-technical audiences.
- Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture.
- Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes.
- Identifies the impact of security test plans on upstream and downstream solution components.
- Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×