← к выдаче
безопасность

Application Security Consultant

вчера

Описание от работодателя

Who We Are – MassMutual Romania MassMutual Romania is a technology partner of MassMutual, a leading financial services company in the U.S., with a more than 170-year legacy. Established in 2020, the Romanian company is building an in-house team passionate about technology and innovation. We have expertise in software development, data science, and a wide range of technologies. With offices in Bucharest and Cluj, and team members across the country, MassMutual Romania develops technological solutions that help MassMutual deepen its digital capabilities and accelerate its growth in a digital-first world. Job Description Job Description We are seeking a highly skilled and experienced Application Security Engineer/Consultant to advance our application security initiatives, with a particular emphasis on dynamic application security testing (DAST). You will own and mature how we test running applications and APIs for exploitable weaknesses, drive secure development practices, and implement solutions that protect our systems and data from evolving threats. The role partners with development teams, security architects, leadership, and other stakeholders to embed security into every stage of the software development lifecycle. Our Application Security team keeps MassMutual's software applications secure through rigorous assessment and proactive development team engagements. We work closely with security architects, DevOps engineers, and software developers, while our core focus is identifying and verifying vulnerabilities — including hands-on dynamic testing of running applications and APIs — implementing security best practices, and helping development teams remediate. Our backgrounds span software engineering to red teaming, and we value continuous learning, innovation, and collaboration. Responsibilities · Own and advance our dynamic application security testing (DAST) program — selecting, deploying, configuring, and maintaining DAST tooling across our web application and API estate. · Design and run authenticated dynamic scans against complex applications, including session handling, multi-step workflows, single-page applications, and REST/GraphQL APIs. · Integrate DAST into CI/CD pipelines and pre-production environments so dynamic testing runs continuously rather than as a point-in-time exercise, and define the thresholds that gate a release. · Triage, validate, and tune DAST output — eliminating false positives, confirming exploitability through manual verification, and translating findings into actionable remediation guidance for development teams. · Complement automated dynamic testing with manual techniques to identify, risk-assess, and prioritize application-level vulnerabilities (e.g., OWASP Top 10) that scanners alone do not surface. · Conduct in-depth security assessments, including vulnerability scanning and code review. · Conduct detailed threat modeling to identify attack vectors and potential weaknesses, and use the results to focus dynamic test coverage where risk is highest. · Collaborate with security architects to design secure application architectures aligned to industry best practices, ensuring secure coding practices are followed and security controls are built into software designs. · Partner with our SDLC Council to develop and maintain secure coding standards that empower developers to integrate security into their own workflow. · Partner with DevOps teams to implement security controls within CI/CD pipelines for automated, seamless deployment of secure code. · Maintain the broader application security testing toolchain, including static analysis (SAST) and software composition analysis (SCA), alongside DAST. · Evaluate third-party software and APIs for security compliance, including dynamic testing of externally sourced components where appropriate. · Support incident response for application security events, providing rapid identification and mitigation guidance. · Ensure compliance with applicable security regulations, frameworks, and industry standards. · Use reporting tools to communicate vulnerability and code-defect risk to MassMutual's cyber assets through metrics (KPIs, KRIs, OKRs), enabling team leaders and executive leadership to make risk-based prioritization decisions. · Educate developers and stakeholders on secure coding practices and on interpreting and acting on dynamic test results. · Stay current on security threats, vulnerabilities, and industry trends, and apply them to improve our security strategy. Requirements · Bachelor's or master's degree in Computer Science, Information Security, or a related field. · 5+ years of experience in application security, penetration testing, or secure software development. · Demonstrated hands-on experience with dynamic application security testing (DAST) of web applications and APIs. The Ideal Qualifications · Deep, hands-on expertise with DAST tooling (e.g., Burp Suite, OWASP ZAP, Invicti, Acunetix, StackHawk) including authenticated scan configuration, scan policy tuning, and API scanning. · Experience operationalizing DAST at scale — pipeline integration, scheduled scanning across a large application estate, results triage workflows, and reducing false-positive rates over time. · Relevant security certifications such as CEH, OSCP, CISSP, or GWAPT from an industry-recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2). · Strong knowledge of secure software development methodologies, including threat modeling, code review, and static/dynamic analysis. · Deep understanding of common application vulnerabilities (e.g., OWASP Top 10) and their mitigations, with the ability to manually verify and exploit findings to confirm real risk. · Experience integrating security into DevOps (DevSecOps) and CI/CD environments. · Strong technical knowledge of web application security, cloud security (AWS, Azure, GCP), mobile security, infrastructure as code, containerized environments (Docker, Kubernetes), and API security. · Hands-on experience across the wider testing toolchain — SAST, SCA, IAST, and fuzzing tools. · Experience identifying security defects in container images and Kubernetes environments. · Advanced proficiency writing source code in at least one programming language (e.g., Java, JavaScript, C/C++/C#, Python) and familiarity with common build and dependency tooling (e.g., Maven, Gradle, Node). · Experience with cloud deployment and automation tooling (Terraform, GitHub Actions, Jenkins, AWS CloudFormation, secrets managers). · Experience using AI tools (Claude Code, Copilot, Codex) to automated processes and perform security analysis of web applications and API, including building skills and agents. · Working knowledge of encryption, authentication, and access control. · Knowledge of compliance and regulatory frameworks (e.g., SOC 2). · Strong analytical and problem-solving ability, with excellent communication skills — able to explain security issues to both technical and non-technical stakeholders. · A collaborative team player comfortable in a fast-paced environment. Who We Are – MassMutual Romania MassMutual Romania is a technology partner of MassMutual, a leading financial services company in the U.S., with a more than 170-year legacy. Established in 2020, the Romanian company is building an in-house team passionate about technology and innovation. We have expertise in software development, data science, and a wide range of technologies. With offices in Bucharest and Cluj, and team members across the country, MassMutual Romania develops technological solutions that help MassMutual deepen its digital capabilities and accelerate its growth in a digital-first world. #LI-PD1