Security Consultant
The skills required are for Security Consultant (CISSP certified is desired, additional certifications would be beneficial), the candidate should be comfortable with at least one of the following:
• Computer networking
• Application security
• Cryptography (desirable not essential)
• Pentesting experience
• Databases
• Operating systems such as Linux and Windows
Integrate security into SDLC and CI/CD pipelines.
Support SAST, SCA, IaC, and dependency scanning for applications and infrastructure.
Provide developer guidance and remediation support for identified vulnerabilities.
Promote secure-by-design and DevSecOps practices across development teams.
Collaborate with engineering and security teams to improve application security posture.
DevSecOps implementation and secure SDLC practices
Static Application Security Testing (SAST) and Software Composition Analysis (SCA)
Infrastructure-as-Code (IaC) security and dependency scanning
Developer guidance and vulnerability remediation
Secure-by-design principles and application security best practices