Offensive Security Penetration Tester
Korn Ferry · Heredia
Job description
About the role
The Offensive Security Penetration Tester (Application Security Consultant) is a senior‑level position responsible for embedding security throughout the software development lifecycle. The role combines manual and automated testing, secure code reviews, and close collaboration with developers and DevOps teams to reduce vulnerability exposure.
Key responsibilities
- Review application source code for security flaws using manual analysis and automated tools (DAST, SAST).
- Integrate application security services into CI/CD pipelines and work with DevOps to enforce secure practices.
- Provide one‑on‑one guidance to developers on identified vulnerabilities and remediation strategies.
- Deliver training sessions for DevOps personnel and developers on security tooling.
- Continuously assess production applications, tune web application firewalls, and review security alerts.
- Conduct secure code reviews, static and dynamic testing, open‑source component analysis, and mobile app security assessments.
- Lead threat‑modeling exercises and security architecture reviews.
- Collaborate with vendors on third‑party application assessments.
- Define and present secure development standards and influence architectural decisions.
- Communicate risk and recommendations clearly to technical teams and executive stakeholders.
Required profile
- Senior‑level professional with advanced programming skills in Java, Python, Swift or similar languages.
- Hands‑on experience with application security tools (e.g., Checkmarx, Black Duck, NowSecure, Burp Suite, Sonatype).
- Proven ability to conduct threat modeling and lead security architecture reviews.
- Experience working with vendors on third‑party assessments.
- Strong capability to define, document, and present secure development standards.
- Excellent cross‑functional communication skills for interacting with developers, product owners, and executives.
Required skills
- Java
- Python
- Swift
- Checkmarx (or similar SAST tool)
- Black Duck (or similar OSCA tool)
- NowSecure or comparable mobile security solution
- Burp Suite
- Sonatype Nexus/Repository Manager
- SAST, DAST, OSCA
- Web Application Firewall (WAF) tuning
- Threat modeling
- Security architecture review
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Costa Rica.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 2 weeks from now
65 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Korn Ferry
Heredia