ABOUT KALLES GROUP:
Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.While our expertise spans multiple disciplines, our method remains consistent: building trust and relationships with people -- whether you are a client, a consultant, or--in this case--a candidate.No matter what role you come from--whether you're an executive or just starting your career-you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.We believe the best way to show you what our team is like is to treat you like you're already a part of it.
We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group—and having fun while doing it.
WHAT YOU WILL DO:
The Application Security Consultant will focus on the implementation and maturation of secure development practices for our finance client. This role involves operationalizing secure development, configuring security scanning tools, and integrating these practices into the software development lifecycle. The ideal candidate will have a strong background in information security, experience with secure development, and the ability to collaborate with various stakeholders to ensure compliance and efficiency.
You will:
- Confirm the scope of secure development practices and solutions (e.g., GitHub Advanced Security for secrets scanning, static scanning, open-source scanning).
- Identify in-scope applications and associated source code repositories.
- Verify security severity ratings and align them with remediation timelines.
- Develop training solutions and approaches for both developers and information security personnel.
- Configure and refine security scanning tools for in-scope repositories.
- Optimize scanning configuration to balance comprehensive coverage and false positive rates.
- Validate all critical and high-priority findings as true positives and ensure correct severity ratings.
- Collaborate with developers for validation as familiarity with in-scope applications grows.
- Integrate security scanning into the software development lifecycle, triggering scans at appropriate stages.
- Document processes and procedures as needed.
- Train engineers on scanning configuration and vulnerability validation processes.
- Define and configure reporting to measure scanning services and remediation performance.
- Review reports with security engineers and leadership, iteratively refining to meet business needs.
ABOUT YOU:
- Your values:
- Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
- Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
- Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
Your experience:
- Bachelor’s degree in Information Technology, Computer Science, or a related field.
- Minimum of 7-10 years of experience in information security, secure development practices, or a related field.
- Proven experience with configuring and optimizing security scanning tools.
- Strong understanding of secure development lifecycle and best practices.
- Experience with GitHub Advanced Security or similar tools.
- Proficient in documenting processes and creating Standard Operating Procedures (SOPs).
- Excellent communication and stakeholder management skills.
- Ability to work independently and manage multiple tasks effectively.
- Strong analytical and problem-solving skills.
- Consulting experience is a plus!
Preferred Certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- Certified Information Security Manager (CISM)
- Offensive Security Certified Professional (OSCP)
- Secure Software Practitioner (CSSLP)
- GIAC Web Application Penetration Tester (GWAPT)
WHAT WE OFFER:
- Competitive compensation with opportunities for additional incentives. The annual salary for this role is $175-195K/year. We welcome C2C applicants at $118-128/hour.
- Work/life balance – we know there’s more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.
- Opportunities to connect in person and remotely with a passionate, supportive team.
LOCATION:
Kalles Group is steadily growing our talent pool across the USA! We are currently able to hire in the following states: Arizona, California, Georgia, Illinois, Maryland, Michigan, Minnesota, North Carolina, Ohio, Oregon, and Washington. If you would like to request more information, please reach out to talent@kallesgroup.com.
HOW TO APPLY:
Please fill out the form below (including uploading your most recent resume) and we'll be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope you'll still consider applying. That's why we've made the application process as short and simple as possible.Even if you're not a fit for the role, you can expect to hear back from us! We want you to have the best experience as a candidate, so please feel free to share feedback at any stage of the process to talent@kallesgroup.com.Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.