
Technical Security Consultant
- Penetration Testing
- SAST
- DAST
- CI/CD
- OSCP
- GPEN
- CEH
- CISSP
- OWASP
- NIST
- ISO 27001
- Network Security
- Agile
- AWS
- Azure
- GCP
- Google Workspace
About the job
As aTechnical Security Consultant, you'll be an integral part of our Digital Security division at SAI, working within a multidisciplinary team. Your primary role will be to identify and deliver high-value digital security advisory services to our clients, with a strong focus on technical security assessments and penetration testing. The ideal candidate will be passionate about discovering new security vulnerabilities, collaborating with diverse stakeholders to improve business outcomes, and sharing knowledge. Our team is composed of experienced and junior consultants with a wide range of specialties.
Responsibilities
Conduct comprehensivepenetration tests on web applications, mobile applications, and network infrastructure to identify vulnerabilities and security flaws.
Performstatic and dynamic analysis (SAST/DAST) on a variety of codebases and platforms to discover security vulnerabilities and provide actionable remediation steps to development teams.
Work with internal and external customers to scope security assessments, explain the methodology, and support them with feedback and verification during the mitigation phase.
Recommend and implement industrybest practices for vulnerability and threat management.
Enforcesecure CI/CD practices by integrating security tools like SAST and dependency checkers into the development pipeline.
Collaborate with development teams to fix identified vulnerabilities and provide guidance on secure coding techniques.
Develop and delivertraining on secure coding and security awareness for technical staff.
Contribute to the design and implementation of secure SDLC (Software Development Life Cycle) andsecurity-by-design principles.
Qualifications
5+ years of experience in delivering technical security services, including penetration testing, vulnerability assessments, and infrastructure security reviews.
Demonstrated experience withweb and mobile application security and the ability to discover vulnerabilities in source code and application design.
Security qualification(s) such asOSCP, GPEN, CEH, CISSP, or other relevant penetration testing and security certifications.
Strong knowledge and application ofinformation security frameworks and methodologies such as OWASP, NIST, and ISO 27001.
Advanced understanding ofsecurity protocols, cryptography, and network security concepts.
Proven track record of working on complex projects in diverse environments.
Strong analytical andproblem-solving skills with a customer-oriented approach.
Familiarity with Agile processes and principles.
Desirable
Experience withcloud security assessments (AWS, Azure, GCP).
Competence inproject management best practices.
Experience withGoogle Workspace solutions and SaaS technologies.
Technical Security Consultant ยท Shawne Applebee