The Company
ISA Consulting is an IT company offering end-to-end solutions in Digital Transformation, Digital Consulting and Business Process Services - supporting all Tech Stacks. Collectively we service a multitude of clients across industries and company verticals. We are a culmination of some of the brightest Full Stack Developers, Data Engineers, Architects, Project Managers, Quality Analysts, Strategists, spanning across multiple time zones.
Job Summary
We are looking for an Application Security Engineer to help secure our eDiscovery and AI platform across the full software development lifecycle. The role is focused on manual secure code review and application security testing, and on partnering with engineering teams to find and fix vulnerabilities before they reach production. The work is hands-on and technically varied. You will review code across multiple products, languages, and frameworks, own reviews end to end, and help build the tooling and automation that support them. A successful candidate is a strong technical communicator who can work independently, write clear and evidence-backed findings, and drive them to closure with engineering.
Responsibilities & Duties
Code Review & Assessment
- Perform in-depth manual, tool-assisted, and AI-assisted code reviews to identify vulnerabilities before release.
- Own assigned reviews end to end, from scoping and repository identification through written findings and remediation follow-up.
- Independently resolve or escalate blockers; drive engagement with engineering teams without requiring day-to-day direction.
- Produce complete, evidence-backed review reports with severity ratings, reproduction detail, and remediation guidance, tracked to closure in Jira against defined SLAs.
- Partner with engineering teams to triage and remediate findings from code review, SAST/DAST, and other assessment tooling.
Security Engineering & SDLC
- Contribute to security reviews for new products, features, and services.
- Provide input on secure design, architecture, and implementation decisions.
- Apply secure development lifecycle practices, including threat modeling and security testing.
- Own dependency and supply chain risk (SCA, SBOM, vulnerability triage) and help extend security controls into CI/CD pipelines.
- Partner with Security Operations and Infrastructure teams to build security tooling and automation.
Influence & Enablement
- Create clear security guidance and documentation for engineering teams.
- Contribute to security training and the Security Champions program.
Requirements & Skills
- Serves as a role model and promotes professional behavior.
- Must possess excellent written and verbal communication skills with people in multiple disciplines and levels of the organization.
- Willing to get involved in multiple projects, assignments and IT competency areas.
- Open minded and solutions-oriented.
- Strong troubleshooting and problem-solving skills.
- Passion to deliver exceptional customer service experience to all employees.
Education & Experience
- Bachelor's degree in a relevant field (Computer Science, Software Engineering, Security, or similar), or an equivalent combination of education, training, and experience.
- Minimum of 3-5 years of professional experience in application security or software engineering, with at least 2 years focused on secure code review, application security testing, or secure development.
- Hands-on software development experience sufficient to read and reason about production code.
- Professional experience conducting security assessments, including manual secure code review.
- Professional experience building or reviewing threat models.
- Experience with SAST, DAST, and SCA tooling (e.g. Semgrep, CodeQL, Burp Suite, Dependency-Track).
- Ability to read and review unfamiliar codebases across multiple languages (C#/.NET, Node/TypeScript, Java, Python, Ruby).
- Understanding of the HTTP protocol, web frameworks, and web and cloud architectures.
- Understanding of cryptography as it appears in application code: key handling, secrets management, encryption in transit and at rest.
- Familiarity with multi-tenant SaaS security, particularly tenant isolation and access control.
- Experience using AI-assisted tooling (e.g. Claude Code, Copilot) in code review or triage workflows.
- Familiarity with LLM/GenAI application security: prompt injection, insecure output handling, data leakage via retrieval pipelines. OWASP Top 10 for LLM Applications.
- Familiarity with reverse engineering or vulnerability research.
- Experience in a compliance-bound environment (FedRAMP, SOC 2, ISO 27001).