Senior Application Security Consultant in Morris Plains
Listed on 2026-09-05
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
Application Security Consultant
Our client is seeking a hands-on Application Security Consultant to support and mature its enterprise application security program. The ideal candidate will have recent App Sec experience across secure development, SAST/SCA, vulnerability management, AWS security, secure code review, and Dev Sec Ops . The consultant will work closely with development, cloud engineering, cybersecurity, and business teams to identify security risks, support remediation, and ensure applications are securely designed, developed, and deployed.
Key Responsibilities
- Lead application security reviews across web, mobile, API, and cloud-native applications.
- Administer and optimize Checkmarx and Snyk, including scanning, ruleset tuning, findings triage, and remediation tracking.
- Apply OWASP Top 10 principles to identify and remediate application and API vulnerabilities.
- Perform secure code review and validate findings using JavaScript, Node.js, Java, or Python.
- Secure AWS environments, including Lambda, API Gateway, IAM, and S3.
- Work with cloud security platforms such as Wiz, Orca Security, or Prisma Cloud.
- Integrate security controls into CI/CD and Dev Sec Ops pipelines.
- Support application-layer protection, production releases, change management, and go-live activities.
- Partner with developers and engineering teams to drive vulnerability remediation and secure coding practices.
- Represent Application Security in architecture, project planning, and risk discussions.
- Prepare security reports and track remediation activities.
Required Qualifications
- 3+ years of recent, hands-on Application Security experience.
- Strong experience with SAST/SCA, particularly Checkmarx and Snyk.
- Strong knowledge of OWASP Top 10, web/API vulnerabilities, and remediation techniques.
- Hands-on AWS security experience with Lambda, API Gateway, IAM, and S3.
- Experience with Wiz, Orca Security, or Prisma Cloud.
- Ability to read and understand code in JavaScript, Node.js, Java, or Python.
- Experience with secure code review, vulnerability triage, Dev Sec Ops , CI/CD, and Agile.
- Experience working with development teams and production release/change management.
- Strong communication and stakeholder-management skills.
Ideal Candidate
The strongest candidates will have current App Sec experience, hands-on knowledge of modern security tools and cloud environments, and the ability to understand code and work directly with developers on remediation.
Important:
Candidates must be able to work onsite Tuesday-Thursday in Parsippany, NJ.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).