Senior Application Security Consultant
Lead application security initiatives for global enterprises by performing in-depth security assessments, threat modeling, and secure code reviews. Collaborate with development teams to integrate security best practices into the software development lifecycle. Requires proven expertise in SAST/DAST/SCA tools, OWASP Top 10, and secure coding standards with hands-on experience in enterprise environments.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Are you an experienced Application Security Consultant passionate about helping development teams build secure, resilient, and trustworthy applications? Join Wypoon Technologies and play an important role in strengthening application security capabilities, identifying technical risks, and supporting secure software development across complex enterprise environments.
In this role, you will perform in-depth secure code reviews, application security assessments, threat modelling, and security architecture reviews. You will work closely with software engineers, architects, security teams, and business stakeholders to validate vulnerabilities, prioritize remediation activities, and translate complex technical findings into clear and actionable recommendations. You will also support the implementation and effective use of application security tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
Why Join Us?
At Wypoon Technologies, you’ll work on dynamic projects for industry leaders such as Heineken, ING, ASML, Philips, and Shell, tackling exciting challenges and delivering tailored enterprise solutions.
Here’s what makes us stand out:
✔ Impactful Work: Shape the future of our clients’ digital landscapes.
✔ Innovative Environment: Collaborate within a supportive team that values learning and growth.
✔ State-of-the-art technology: Access the latest tools and platforms.
✔ Global Opportunities: Are you dreaming of living and working in the Netherlands or Belgium? We provide full support with visa processes, making your transition smooth and hassle-free!
- Application Security Assessments: Conduct comprehensive security assessments of applications, services, APIs, and supporting architectures to identify vulnerabilities and security design weaknesses.
- Secure Code Reviews: Perform in-depth manual and tool-assisted code reviews to validate security findings, identify vulnerabilities, and assess compliance with secure coding standards.
- Threat Modelling: Facilitate and deliver threat models for new and existing applications, identifying potential attack paths, abuse cases, security controls, and recommended mitigations.
- Security Architecture Reviews: Review application and cloud architectures and provide practical security recommendations during software development projects and technology initiatives.
- SAST, DAST and SCA: Utilize, configure, and support application security testing tools, including Static Application Security Testing, Dynamic Application Security Testing, and Software Composition Analysis solutions.
- Vulnerability Validation: Validate automated security findings, eliminate false positives, evaluate exploitability, and determine the potential technical and business impact of identified vulnerabilities.
- Risk Prioritization: Assist development and security teams in prioritizing vulnerabilities based on severity, exploitability, application criticality, and enterprise risk.
- Remediation Support: Work closely with software development teams to define effective remediation actions and ensure security findings are resolved within agreed timelines.
- Secure Software Development: Support the adoption of secure coding practices, security-by-design principles, and application security controls throughout the software development lifecycle.
- Security Standards and Guidance: Develop or improve application security standards, technical guidance, review processes, and reusable security patterns.
- Stakeholder Advisory: Communicate application security risks to technical and non-technical stakeholders and translate complex findings into clear, actionable business language.
- Risk Reduction: Complete an agreed number of application security assessments per quarter and contribute directly to reducing security risks across the organization.
Looking to advance your Cyber Security career with relocation support? Explore Cyber Security Jobs with Relocation Packages that include comprehensive packages to help you move and settle in your new role.
- Application Security Experience: Proven professional experience in application security, product security, software security, penetration testing, secure software development, or a similar cybersecurity position.
- Secure Code Review: Strong hands-on experience performing secure code reviews and identifying vulnerabilities in application source code.
- Application Security Testing: Practical experience with SAST, DAST, and SCA tools and the ability to validate and interpret automated security findings.
- Security Assessments: Demonstrated ability to perform complex application security assessments and deliver clear remediation recommendations.
- Threat Modelling: Experience conducting threat modelling and identifying attack scenarios, trust boundaries, security risks, and appropriate controls.
- Application Security Knowledge: Strong understanding of common application vulnerabilities, attack techniques, secure coding practices, and application security architecture.
- OWASP Knowledge: Strong knowledge of the OWASP Top 10 and other relevant application security standards, methodologies, and vulnerability classifications.
- Vulnerability Management: Experience validating, prioritizing, documenting, and supporting the remediation of security vulnerabilities.
- Cloud Security: Understanding of cloud security principles and security considerations for applications deployed in cloud or hybrid environments.
- Software Development Lifecycle: Understanding of modern software development practices and how security activities can be integrated throughout the development lifecycle.
- Technical Communication: Ability to explain complex application security risks and technical vulnerabilities to developers, architects, managers, and business stakeholders.
- Stakeholder Management: Strong advisory, collaboration, and stakeholder management capabilities, with the ability to influence development teams and project stakeholders.
- Ownership and Independence: High degree of ownership, independence, accountability, and the ability to manage multiple security assessments and priorities simultaneously.
- Language Skills: Professional proficiency in English, covering speaking, writing, listening, and reading.
Discover our full range of relocation jobs with comprehensive support packages to help you relocate and settle in your new location.
- Experience working within large enterprise, financial services, banking, insurance, fintech, telecommunications, or other regulated environments.
- Experience integrating application security tools and controls into CI/CD pipelines and DevSecOps processes.
- Knowledge of secure development frameworks and standards such as OWASP ASVS, OWASP SAMM, NIST Secure Software Development Framework, or similar methodologies.
- Experience assessing web applications, APIs, microservices, mobile applications, and cloud-native application environments.
- Understanding of authentication, authorization, session management, cryptography, API security, and identity-related application vulnerabilities.
- Experience with application security tools such as Checkmarx, Fortify, Veracode, Semgrep, SonarQube, Snyk, Black Duck, Mend, Burp Suite, OWASP ZAP, or comparable solutions.
- Ability to review source code in one or more programming languages such as Java, C#, JavaScript, TypeScript, Python, Go, C, or C++.
- Experience with cloud platforms such as Microsoft Azure, Amazon Web Services, or Google Cloud Platform.
- Familiarity with container security, Kubernetes security, infrastructure as code, and cloud-native software architectures.
- Knowledge of security and compliance frameworks such as ISO 27001, NIST Cybersecurity Framework, SOC 2, GDPR, DORA, or NIS2.
- Relevant certifications such as CISSP, CSSLP, OSWE, GWAPT, CEH, cloud security certifications, or equivalent application security qualifications.
- Familiarity with Agile methodologies and collaboration tools such as Jira, Azure DevOps, and Confluence.
Interested in relocating to Netherlands? Check out our comprehensive Relocation Jobs in Netherlands page with detailed relocation packages and benefits.
- Competitive Compensation: Salary tailored to your skills and experience.
- Generous Time Off: 25 paid vacation days (based on a 40-hour work week).
- Job Security: A direct and permanent contract from day one!
- Relocation Support: A relocation and travel budget to ease your transition.
- Tax Benefits: Eligibility for the 30% ruling.
- Travel Reimbursement: We've got your daily commute covered.
- Top-Notch Equipment: A high-quality device to ensure you work efficiently.
- Professional Development: Financial support for certifications, technical training, and language courses—because we value your long-term career growth.
- Family: Visa sponsorship for your partner and children under 18.
- Temporary Accommodation: Stay in temporary housing while we help you find your permanent home.
- Comprehensive Relocation Assistance: Extensive support to help you settle in smoothly.
- Community & Fun: Enjoy team events and connect with developers from around the globe!
Join Wypoon Technologies, where your expertise will thrive, your ideas will be valued, and your career will reach new heights.
Apply now to help build the future of IAM solutions and make a real impact!
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Similar Jobs
Explore other opportunities that match your interests