Application Security Advisor / Trainer (Contractor)

Iconma LLC

  • Atlanta, GA
  • 8 days ago

    Highlights

    Responsibilities: Advise and support application development teams on interpreting and remediating application security findings (static analysis / SAST, software composition analysis / SCA, secrets, API, container, and infrastructure-as-code scanning). Deliver enablement and training (working sessions, office hours, guides) that help developers understand common vulnerability patterns (CWEs) and the steps to fix them.

    Numbers & Facts

    LocationAtlanta, GA

    Description

    Our client, a Commercial Banking company, is looking for a Application Security Advisor / Trainer (Contractor) for their Remote location.

    Responsibilities:

    • Advise and support application development teams on interpreting and remediating application security findings (static analysis / SAST, software composition analysis / SCA, secrets, API, container, and infrastructure-as-code scanning).
    • Deliver enablement and training (working sessions, office hours, guides) that help developers understand common vulnerability patterns (CWEs) and the steps to fix them.
    • Create and maintain self-service documentation, remediation playbooks, and training material.
    • Partner with security and DevOps teams to support pipeline security integration and vulnerability burndown.
    • Track remediation progress and help teams prioritize work by risk."

    Requirements:

    • Foundational hands-on programming / coding experience (e.g., Java, Python, JavaScript, C#, or similar).
    • Understanding of core application security concepts (OWASP Top 10, secure coding, common vulnerability classes / CWEs).
    • Familiarity with application security scanning concepts (static analysis, software composition analysis, secrets scanning).
    • Ability to explain technical security concepts clearly to developers (strong written and verbal communication).
    • Experience creating documentation or delivering training / enablement content.
    • Exposure to CI/CD pipeline security integration.
    • Familiarity with container and cloud security scanning concepts.
    • Experience with vulnerability management workflows and ticketing.
    • Relevant coursework, internships, certifications, or personal projects in application or security engineering.

    Why Should You Apply?

    • Health Benefits
    • Referral Program
    • Excellent growth and advancement opportunities