
Application Security Cosultant
CyderesPosted 5/26/2025

Application Security Cosultant
Cyderes
Job Location
Job Summary
Cyderes is seeking an Application Security Consultant to guide clients from traditional DevOps practices to a comprehensive DevSecOps model. The role involves conducting in-depth code reviews, utilizing DAST, SAST, and SCA tools for security assessments, and performing web application penetration tests. The ideal candidate has extensive experience in application and code security, static and dynamic code analysis solutions, and cloud integration. They should also possess strong technical writing skills and a bachelor's degree or equivalent in professional experience. This full-time remote position offers flexible work options, $4,000/year travel stipends, and equity in a fast-growing company.
Job Description
Responsibilities
- Lead security reviews and web application penetration tests to identify vulnerabilities across a variety of development frameworks and languages.
- Advise on the integration of security practices within DevOps processes, aiding in the transition to DevSecOps.
- Perform thorough code reviews using DAST, SAST, and SCA tools, focusing on a wide array of programming languages.
- Work closely with development teams to instill secure coding practices and embed security measures within CI/CD pipelines.
- Support the bug bounty program.
- Support the preparation of security releases.
- Assist in development of security processes and automated tooling that prevent classes of security issues.
Requirements
- Extensive experience application and code security
- Experience with static and dynamic code analysis solution. For Example: Veracode, Checkmarx, SonarQube
- Retain one or more of the following certifications: CISSP, CISM, OSCP, CEH
- Experience in solution architecture, DevSecOps practices, and cloud integration.
- Experience working with Infrastructure as Code, CI/CD pipelines and Secure DevOps processes.
- Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (OAuth, OpenID, SAML, etc.).
- Strong expertise in at least one of the major programming languages (e.g., C/C++, Java, Python). This foundational knowledge is crucial for conducting effective code reviews and security assessments.
- An understanding of, or experience with, a diverse set of languages, including but not limited to Gosu, Business Basic, CLI Scripts, HCL Domino, Net.Data, PowerShell, Shell, SQL, and SQR.
- 2-3 years overall application security experience
- Strong security inclination
- Strong technical writing skills
- Bachelor’s degree or equivalent in professional experience