Application Security Consultant
vTech Solution
The Application Security Senior Consultant serves as the technical authority responsible for conducting expert manual secure code reviews and security assessments of enterprise applications, primarily focusing on large C#/.NET codebases. This role identifies security weaknesses that automated tools may miss and ensures the accuracy and actionability of findings delivered to stakeholders. The consultant leads architecture reviews, assesses multiple security dimensions, prioritizes risks, and provides detailed remediation guidance to enhance the security posture of critical financial and transaction-processing applications. Responsibilities:
- Lead architecture walkthroughs with application and development subject matter experts (SMEs).
- Establish and validate read-only source code access under least privilege principles.
- Create technology and framework inventories for each application assessed.
- Develop criticality-weighted coverage plans focusing manual review on business-critical code paths.
- Perform manual secure code reviews across architecture, access control, data protection, business logic, and security-sensitive code paths.
- Map trust boundaries, data flows, and external system interactions per application.
- Construct and test abuse cases against critical business rules and transaction logic.
- Trace and verify authorization enforcement workflows and separation of duties.
- Assess cryptographic implementations, key lifecycle, and secrets management.
- Escalate confirmed high-impact findings within 4 business hours.
- Assign CVSS v3.1 base and environmental ratings to findings and agree on environmental context.
- Author prescriptive remediation guidance specific to the C#/.NET codebase.
- Identify root-cause patterns across applications and contribute to technical and strategic report sections.
- Lead technical findings discussions and support report presentations to leadership.
- Minimum 6 years of experience in application security.
- Expertise in secure code review of enterprise web applications.
- Strong knowledge of web application and API security.
- Hands-on experience with C# and .NET development environments.
- Proficiency in manual code analysis techniques.
- Experience with commercial static analysis (SAST) tools.
- Understanding of authentication and authorization architectures.
- Knowledge of secure Software Development Life Cycle (SDLC) practices.
- Relevant application security or offensive security certifications such as OSWE, GWAPT, CSSLP, or CISSP.
- Experience delivering services to the public sector or Commonwealth of Virginia.
- Familiarity with security standards and frameworks including NIST SP 800-53, COV SEC530, OWASP ASVS, and CWE.
- Domain knowledge of financial or transaction-processing applications.
- Immediate escalation of high-impact security issues within 4 business hours is required.
- Read-only source code access must be established and maintained under least privilege principles.
- Work schedule will align with project phases including discovery, assessment, reporting, and knowledge transfer.
- Availability to respond promptly to critical findings during assessment phases.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Consultant. Be the first to apply!
- security consultant Richmond, VA
- IT security analyst Richmond, VA
- senior security analyst Richmond, VA
- security advisor Richmond, VA
- application security analyst Richmond, VA
- entry level security analyst Richmond, VA
- security coordinator Richmond, VA
- work from home security analyst Richmond, VA
- information security compliance analyst Richmond, VA
- security analyst Richmond, VA
