Offensive Security Penetration Tester
Korn Ferry · Heredia
Descripcion del puesto
About the role
The Offensive Security Penetration Tester (Application Security Consultant) is a senior‑level position responsible for embedding security throughout the software development lifecycle. The role combines manual and automated testing, secure code reviews, and close collaboration with developers and DevOps teams to reduce vulnerability exposure.
Key responsibilities
- Review application source code for security flaws using manual analysis and automated tools (DAST, SAST).
- Integrate application security services into CI/CD pipelines and work with DevOps to enforce secure practices.
- Provide one‑on‑one guidance to developers on identified vulnerabilities and remediation strategies.
- Deliver training sessions for DevOps personnel and developers on security tooling.
- Continuously assess production applications, tune web application firewalls, and review security alerts.
- Conduct secure code reviews, static and dynamic testing, open‑source component analysis, and mobile app security assessments.
- Lead threat‑modeling exercises and security architecture reviews.
- Collaborate with vendors on third‑party application assessments.
- Define and present secure development standards and influence architectural decisions.
- Communicate risk and recommendations clearly to technical teams and executive stakeholders.
Required profile
- Senior‑level professional with advanced programming skills in Java, Python, Swift or similar languages.
- Hands‑on experience with application security tools (e.g., Checkmarx, Black Duck, NowSecure, Burp Suite, Sonatype).
- Proven ability to conduct threat modeling and lead security architecture reviews.
- Experience working with vendors on third‑party assessments.
- Strong capability to define, document, and present secure development standards.
- Excellent cross‑functional communication skills for interacting with developers, product owners, and executives.
Required skills
- Java
- Python
- Swift
- Checkmarx (or similar SAST tool)
- Black Duck (or similar OSCA tool)
- NowSecure or comparable mobile security solution
- Burp Suite
- Sonatype Nexus/Repository Manager
- SAST, DAST, OSCA
- Web Application Firewall (WAF) tuning
- Threat modeling
- Security architecture review
Questions fréquentes
Por que reporta esta oferta?
Explorar más
Salarios, guías y búsquedas en Costa Rica.
Postula en 30 segundos
Ingresa tu email para postular. Se creara una cuenta automaticamente.
Al continuar, aceptas nuestras condiciones de uso.
Ya tienes cuenta? Iniciar sesion
¿Una pregunta sobre esta oferta?
Hágala aquí: recibirá el resumen completo por correo, de inmediato.
Publicado hace 1 mes
Expira en 2 semanas
64 vistas · 0 interested
Aumenta tus posibilidades
Sube tu CV: te propondremos las ofertas que coinciden con tu perfil.
Analizando tu CV...
Korn Ferry
Heredia