Senior Application Security Engineer - SAST / DAST / Burp Suit - International Organization
hace 12 horas
Valencia
NTT DATA is looking for a Senior Application Security Engineer for one of our international clients, with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services. The successful candidate will lead security assessments, support vulnerability remediation efforts, advise development teams on secure software development practices, and contribute to application security governance, risk, and compliance initiatives. You will be responsible for: • Perform and support application security assessments, including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews., • Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques., • Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness., • Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components., • Lead vulnerability management activities, including identification, prioritization, remediation tracking, and reporting., • Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria., • Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation., • Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices., • Support application security policies, standards, risk assessments, threat modeling, and secure design reviews., • Assist with security compliance and audit-related activities., • Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage., • Communicate security risks and remediation priorities to technical and non-technical stakeholders. For this role you will need to have experience in: • Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience., • 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines., • Strong hands-on experience with:, • SAST, • DAST, • SCA, • Penetration Testing, • API Security Testing, • Manual Security Assessments, • Extensive experience using Burp Suite for web and API security testing., • Hands-on experience with tools such as:, • Burp Suite, • HCL AppScan, • Sonatype Nexus IQ/Lifecycle, • Fortify, • SonarQube, • Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization., • Experience collaborating with development teams to drive remediation and improve security maturity., • Strong written, verbal, and stakeholder communication skills., • Fluency in English (written and spoken)., • Experience with Azure Cloud and Azure DevOps., • Experience with ServiceNow for vulnerability or incident management workflows., • Experience creating security dashboards and reports using Power BI., • Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices., • Experience with AI-assisted security solutions, security automation, or agentic AI technologies., • Certifications: CISSP, CSSLP, GWAPT, GWEB, OSCP / OSWE, Security+, SSCP, Microsoft Azure Security Certifications (AZ-500 or equivalent) NTT DATA is a global consultancy company, employing over 20.000 professionals world-wide. Within the International Institutions we have framework contracts with European Institutions like: European Commission; European Parliament; European Court of Auditors; Europol; NATO; Court of Justice; EPO; European Council, United Nations, etc. #J-18808-Ljbffr