Jobiglo

No results.

Offensive Security Penetration Tester

Korn Ferry · Heredia

Senior 🇬🇧 English
Java Python Swift Checkmarx Black Duck NowSecure Burp Suite Sonatype SAST DAST OSCA Web Application Firewall Threat modeling Security architecture review

Job description

About the role

The Offensive Security Penetration Tester (Application Security Consultant) is a senior‑level position responsible for embedding security throughout the software development lifecycle. The role combines manual and automated testing, secure code reviews, and close collaboration with developers and DevOps teams to reduce vulnerability exposure.

Key responsibilities

  • Review application source code for security flaws using manual analysis and automated tools (DAST, SAST).
  • Integrate application security services into CI/CD pipelines and work with DevOps to enforce secure practices.
  • Provide one‑on‑one guidance to developers on identified vulnerabilities and remediation strategies.
  • Deliver training sessions for DevOps personnel and developers on security tooling.
  • Continuously assess production applications, tune web application firewalls, and review security alerts.
  • Conduct secure code reviews, static and dynamic testing, open‑source component analysis, and mobile app security assessments.
  • Lead threat‑modeling exercises and security architecture reviews.
  • Collaborate with vendors on third‑party application assessments.
  • Define and present secure development standards and influence architectural decisions.
  • Communicate risk and recommendations clearly to technical teams and executive stakeholders.

Required profile

  • Senior‑level professional with advanced programming skills in Java, Python, Swift or similar languages.
  • Hands‑on experience with application security tools (e.g., Checkmarx, Black Duck, NowSecure, Burp Suite, Sonatype).
  • Proven ability to conduct threat modeling and lead security architecture reviews.
  • Experience working with vendors on third‑party assessments.
  • Strong capability to define, document, and present secure development standards.
  • Excellent cross‑functional communication skills for interacting with developers, product owners, and executives.

Required skills

  • Java
  • Python
  • Swift
  • Checkmarx (or similar SAST tool)
  • Black Duck (or similar OSCA tool)
  • NowSecure or comparable mobile security solution
  • Burp Suite
  • Sonatype Nexus/Repository Manager
  • SAST, DAST, OSCA
  • Web Application Firewall (WAF) tuning
  • Threat modeling
  • Security architecture review

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Korn Ferry.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 1 month ago

Expires 2 weeks from now

65 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Korn Ferry

Heredia