Application Security Consultant

AT&T AT&T · Telecom · Brno, Czech Republic

This role focuses on application security, acting as a liaison between development teams and the Chief Security Office. It involves using AI-powered scanners for code analysis, vulnerability identification, and remediation support, as well as monitoring security scorecards and integrating security tools into development workflows.

What you'd actually do

  1. Serve as primary point of contact (POC) for application teams, facilitate effective communication and maintain the escalation matrix.
  2. The ASC will enable AI-powered scanners (SAST/DAST/SCA) to analyze code patterns, reducing false positives and AI-generated fix recommendations directly into developer IDEs.
  3. Foster security awareness and best practices within development teams, nurturing a culture of shared responsibility.
  4. Guide and support development teams in the remediation of identified application security vulnerabilities, providing practical solutions and technical assistance to ensure timely closure of security issues.
  5. Analyze application security scan results (SAST, DAST, SCA etc.), assist teams in resolving findings, and validate false positives.

Skills

Required

  • 12+ years in application security, software development, or information security consulting
  • Demonstrated experience with application security practices including security testing and remediation.
  • Understanding and Exposure to AI enabled Application security Tools and practices.
  • Proficiency in application security principles, vulnerability management, and secure development practices.
  • Experience in performing SAST, DAST and SCA scans.
  • Expertise in Application security vulnerabilities and remediation.
  • Familiarity with threat modeling, risk assessment, and security tool integration
  • Understanding of modern development workflows and DevSecOps concepts
  • Excellent English proficiency (spoken and written)
  • Ability to communicate technical concepts to both technical and non-technical stakeholders
  • Strong analytical, troubleshooting, and problem-solving skills
  • High attention to detail, organizational, and documentation skills
  • Self-motivated and able to work independently and as part of a distributed team

Nice to have

  • Bachelor’s degree (BS/BA) in Computer Science, Information Security, or a related field
  • Certifications such as CISSP, CSSLP or equivalent industry recognized certifications.

What the JD emphasized

  • AI enabled Application security Tools and practices
  • application security practices
  • security testing
  • remediation
  • SAST, DAST and SCA scans
  • Application security vulnerabilities
  • remediation
  • security tool integration
  • DevSecOps concepts