Principal Security Consultant

4 days ago


Minneapolis, United States NetSPI Full time

*US Remote Role*

NetSPI is the proactive security solution used to discover, prioritize, and remediate security vulnerabilities of the highest importance, so businesses can protect what matters most. NetSPI secures the most trusted brands on Earth through Penetration Testing as a Service (PTaaS), External Attack Surface Management (EASM), Cyber Asset Attack Surface Management (CAASM), and Breach and Attack Simulation (BAS). Leveraging a unique combination of dedicated security experts, intelligent process, and advanced technology, NetSPI brings a proactive approach to cybersecurity with more clarity, speed, and scale than ever before.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

NetSPI is seeking a Principal level consultant for our secure code review practice. These individuals will primarily serve as a resource for delivering client assessment services and contribute to practice development.

Responsibilities:

  • Deliver secure code review assessment on programming languages such as Java, C#, C/C++, Python, TypeScript, and JavaScript
  • Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
  • Review vulnerabilities (CVEs) in usage of third-party libraries and determine reachability and exploitability.
  • Develop and review checklists, custom vulnerability description, business impact and remediation strategies.
  • Develop custom rules and patterns to enhance the capabilities of existing SAST Tools.
  • Contribute to development and delivery of secure coding review and development best practices and remediation training
  • Contribute to the development and delivery of secure code review training and secure coding best practices.
  • Collaborate with and assist developers in writing secure software and remediating existing vulnerabilities
  • Mentor and assist team members in effectively delivering assessments and enhancing skillsets
  • Contribute to the community through the development of tools, presentations, white papers, and blogs.
Minimum Qualifications:
  • Minimum of 5+ years of experience in delivering secure code reviews using both manual and automated static analysis techniques.
  • Thorough understanding of the OWASP Top 10 and SANS Top 25 vulnerabilities, with a strong focus on identifying and remediating security issues in source code
  • Proficiency in performing taint analysis, understanding routing mechanisms of various frameworks, and identifying existing mitigating controls within source code
  • Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience
  • Bachelor's degree or higher, preferred with a concentration in Computer Science, Electrical or Computer Engineering, Math, or IT - or equivalent experience.
  • Up to 25% travel
Preferred Qualifications:
  • Experience in detecting, analyzing and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java, C#, C/C++, Python, JavaScript and Typescript
  • Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx, Semgrep, Veracode, Appscan Source, Coverity, Fortify and SonarQube
  • Experience in software development in at least one server-side programming language
  • Web Application pen testing experience
  • OSCP, OSWE, or similar certifications

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.

  • Minneapolis, Minnesota, United States Intuitive Technology Group Full time

    About the RoleWe are seeking a highly skilled Principal Enterprise Security Specialist to join our team at Intuitive Technology Group. As a key member of our security team, you will be responsible for providing expert-level guidance and support for all Oracle application security issues.

  • Principal Energy

    4 weeks ago


    Minneapolis, United States Pioneer Management Consulting Full time

    As a Principal Consultant - Energy & Utilities, you will be a part of a growing team working in a fast-paced environment to help clients solve complex issues and deliver exceptional results. You are a self-driven management consultant who excels at guiding organizations to accomplish their strategic objectives through execution excellence. You have the...


  • Minneapolis, Minnesota, United States Securitas Electronic Security Inc Full time

    Job TitleNational Enterprise Security Solutions ExecutiveAbout the RoleWe are seeking a highly skilled National Enterprise Security Solutions Executive to join our team at Securitas Electronic Security Inc. As a key member of our sales team, you will be responsible for generating new leads, building relationships with existing clients, and driving revenue...


  • Minneapolis, Minnesota, United States ECG Management Consultants Full time

    About ECG Management ConsultantsWith a rich history spanning over five decades, ECG Management Consultants has established itself as a leading consulting firm in the healthcare sector. Our team of experts provides strategic, financial, operational, and technology-related consulting services to hospitals, health systems, medical groups, academic medical...


  • minneapolis, United States Birlasoft Full time

    The Possibilities are Endless When You ChallengeTheNormBirlasoft combines the power of domain, enterprise, and digital technologies to reimagine business processes for customers and their ecosystem. Its consultative and design thinking approach makes societies more productive by helping customers run businesses. As part of the multibillion-dollar diversified...


  • minneapolis, United States Birlasoft Full time

    The Possibilities are Endless When You ChallengeTheNormBirlasoft combines the power of domain, enterprise, and digital technologies to reimagine business processes for customers and their ecosystem. Its consultative and design thinking approach makes societies more productive by helping customers run businesses. As part of the multibillion-dollar diversified...


  • Minneapolis, United States Birlasoft Full time

    The Possibilities are Endless When You ChallengeTheNormBirlasoft combines the power of domain, enterprise, and digital technologies to reimagine business processes for customers and their ecosystem. Its consultative and design thinking approach makes societies more productive by helping customers run businesses. As part of the multibillion-dollar diversified...


  • Minneapolis, Minnesota, United States Merjent Full time

    OverviewMERJENT is a consulting company dedicated to creating an environment where both people and projects succeed. As a Principal Sustainability Specialist, you will work closely with clients and project teams to complete permit acquisitions, assessments, and compliance management for energy-related development projects.SalaryThe anticipated salary for...

  • Engineering Leader

    6 months ago


    Minneapolis, United States Slalom Full time

    Engineering Leader – Principal or Sr. PrincipalThis is a hybrid role aligned to our Minneapolis local market and candidates must be based in/or within commutable distance of the greater Twin Cities area.Who You’ll Work WithAs a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for...

  • EUC Consulting

    3 days ago


    Minneapolis, United States Futran Tech Solutions Pvt. Ltd. Full time

    Role : EUC Consulting Type: Contract Location : Zip code 55344 (Minneapolis, Minnesota, USA) / Local candidates preferred Exp- 5 to 7 year Primary Skill: EUC Consulting Secondary Skill: Desktop Support Job Details : - Identifies correct knowledge documents and support materials to answer questions and troubleshoot issues • Learns about technology...


  • Minneapolis, MN, United States SkyWater Search Partners Full time

    SkyWater Search Partners has engaged with a Twin Cities-based company in the medical device industry to attract and hire a Principal level Software Engineer. If you're looking for a high-impact position at a fast-growing company where you'll be leading and contributing alongside a senior team, we want to hear from you.This company has been around for 10+...


  • Minneapolis, United States Ernst and Young Full time

    At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.The...


  • Minneapolis, Minnesota, United States Infosys Full time

    We are seeking a seasoned System V&V Principal Engineer to join our team at Infosys. This is an exciting opportunity for someone with expertise in software quality assurance, system verification, and test automation.About the RoleThis position will involve collaborating with key stakeholders, applying technical proficiency across different stages of the...

  • IAM Consultant

    4 days ago


    Minneapolis, United States C4 Technical Services Full time

    Position: SAML Consultant Location: 100% remote Required: SAML Expert Okta working with custom apps - 80% java / 20% .net (nice to have) Follow Process: Discovery phase Mobilize plan phase Build and iterate phase Support and transition phase The titles for resources with expertise in SAML who can help with implementing SAML flows for...


  • Minneapolis, Minnesota, United States TriOptus LLC Full time

    At TriOptus LLC, we're seeking an experienced Imaging Informatics Consultant to join our team. As a PACS Admin, you'll be responsible for performing Change Healthcare PACS activities, workflow intelligence support, and system testing.About the RoleThis is a full-time position that offers a competitive salary of $90,000 - $120,000 per year, depending on...


  • Minneapolis, United States Inspire Medical Systems I Full time

    Job DescriptionJob DescriptionABOUT INSPIRE MEDICAL SYSTEMSInspire is the first of its kind medical device designed to make a difference in the lives of those living with Obstructive Sleep Apnea (OSA). We are revolutionizing the sleep industry with our FDA-approved medical device, designed to reduce OSA severity for those who cannot tolerate or get...


  • Minneapolis, MN, United States Birlasoft Full time

    The Possibilities are Endless When You ChallengeTheNormBirlasoft combines the power of domain, enterprise, and digital technologies to reimagine business processes for customers and their ecosystem. Its consultative and design thinking approach makes societies more productive by helping customers run businesses. As part of the multibillion-dollar diversified...

  • Sales Consultant

    4 months ago


    Minneapolis, United States Paychex Full time

    Overview Consult with America's businesses, leveraging Paychex key referral channels and partnerships to educate stakeholders on our services, and provide consultative solutions to increase market share and drive revenue. Responsibilities Achieve unit and revenue expectations. Create, manage, and advance accounts, leads, and opportunities in company’s CRM...


  • Minneapolis, Minnesota, United States Brosnan Risk Consultants Full time

    About the Role: As a Security Patrol Officer at Brosnan Risk Consultants, you will play a vital part in maintaining a secure and positive environment for clients across various sites. You will have opportunities to gain specialized knowledge, develop leadership skills, and respond to incidents effectively.Key Responsibilities:Conduct regular patrols of...


  • Minneapolis, Minnesota, United States RSM Full time

    RSM is a leading provider of professional services to the middle market globally, empowering clients and people to realize their full potential. Our exceptional people are the key to our inclusive culture and talent experience.The Business Development Director will lead all aspects of the sales process, including systematic prospect targeting, development of...