Senior Consultant (Application Security testing - SAST and SCA)
Wipro
· ✓ Verified company
📍 Bengaluru, IND-29, IND, 560035 · On-site · Full-time
About the role
Job Description Profile: Technical Lead (Application Security testing – SAST and SCA) Location: No location constraints (but preference to Pune/Mumbai) Band: B3 Experience: 6–8 years About the role: We are looking to onboard a Senior Consultant (Application Security testing - SAST and SCA) for GCISO unit. R͏oles & Responsibilities • Perform Static Application Security Testing (SAST) across applications (Java, .NET, Node, Angular etc.) • Perform Software Composition Analysis (SCA) to identify vulnerable open-source components and license risks • Configure, execute, and optimize SAST/SCA scans; validate findings and remove false positives • Analyse code-level vulnerabilities and provide clear remediation guidance to developers • Support integration of SAST/SCA into CI/CD pipelines (DevSecOps) working with DevOps engineering team • Track vulnerabilities through closure and support remediation • Deliver secure coding awareness/training sessions to development teams • Must be well versed with alternative secure coding approaches to mitigate the vulnerabilities across different technologies. Q͏ualifications • Bachelor’s degree in a technical field • 6–8 years of experience in application security / SAST / SCA • Strong hands-on experience in SAST tools (e.g., Fortify, Checkmarx, Veracode) and SCA tools (e.g., Sonatype, Black Duck, Snyk) • Good understanding of secure coding practices and OWASP Top 10 • Ability to analyse code (Java, .NET, JavaScript, etc.) and identify vulnerabilities • Experience in scan configuration, tuning, and false positive reduction • Familiarity with CI/CD pipelines and DevSecOps • Good communication skills with ability to deliver developer trainings • Preferred: Prior development experience in any coding language Good to have Certifications: - CEH, GPEN, CISSP, or similar