
Kapalı
İlan edilme:
Teslimde ödenir
• Extensive experience in application security, with a focus on secure software development practices and techniques. • Strong understanding of web application security vulnerabilities and mitigation strategies, such as OWASP Top 10. • Experience with security testing tools and technologies, such as SAST, DAST, and IAST solutions. • Experience with Penetration testing tools such as: (web/mobile: Qualys, Burp Suite) • Experience with cloud security, containerization, and DevSecOps practices is a plus • Proficiency in programming languages commonly used in web application development, such as Java, Python, or JavaScript. • Lead the design and implementation of application security policies, standards, and best practices in alignment with industry standards and regulatory requirements. • Lead a team of application security engineers to develop and drive initiatives to secure products. • Foster a culture of security awareness within the team and across the organization. • Conduct comprehensive security assessments of applications throughout the software development lifecycle (SDLC) to identify and mitigate security vulnerabilities and weaknesses. • Collaborate with software development teams to integrate security controls and best practices into the SDLC, including secure coding standards, static and dynamic code analysis, and security testing. • Provide guidance and support to developers on secure coding techniques, security architecture, and threat modeling. • Manage and oversee application security testing activities, including vulnerability scanning, penetration testing, and code reviews. • Monitor and analyze security incidents related to applications, and coordinate • incident response and remediation efforts as needed. • Stay current with emerging threats, vulnerabilities, and industry trends in • application security. • Develop and deliver application security training and awareness programs for • development teams and other stakeholders. • Collaborate with cross-functional teams to ensure the security of third-party and • open-source software components used in our applications. • Develop and maintain documentation related to application security architecture, • processes, and procedures. • Secure development practices, and integration into broader engineering activities. • Security design / architecture and threat modeling. • Product and service architectures in modern, multi-tenant cloud environments (IaaS, SaaS, PaaS). • Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform (GCP). • Secure operations practices, specifically in cloud environments. • Authentication and Identity management (e.g. SAML, SSO, OIDC, SCIM, etc) security best practices. • Application and infrastructure security testing methodologies and tools. • Vulnerabilities (old and new), and options for defense / mitigation. • Product vulnerability management lifecycle. • Working with and/or supporting product engineering teams. • Security audits, penetration tests, and/or bug bounty programs. • Cryptography and cryptographic primitives. • Strong written and verbal communication skills. • Full SDLC Support for new product features being developed. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc. • Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed. • Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues. • Work on DAST tools and related automation for auto-assessment and defect filing. • Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc. • Prioritize security from a risk management perspective, rather than an absolute textbook version. • Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general • Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow. • Understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography. • Proficient with one or more of Programming languages ( Python/Java/Scala/JavaScript) and ability to read code to identify security defects. • Skilled in scripting and automation on exploits • Fuzzing skills are good to have. • Exploit writing skills is a positive and greatly required.
Proje No: 40056917
31 teklifler
Uzaktan proje
Son aktiviteden bu yana geçen zaman 2 ay önce
Bütçenizi ve zaman çerçevenizi belirleyin
Çalışmanız için ödeme alın
Teklifinizin ana hatlarını belirleyin
Kaydolmak ve işlere teklif vermek ücretsizdir
31 freelancer bu proje için ortalama $146 USD teklif veriyor

When it comes to your project on Advanced Application Security Training, my expertise covers a broad range of key areas that align perfectly with your requirements and will add immense value to your team. Having garnered over a decade's worth of experience as a Certified Ethical Hacker and Penetration Tester, I have the know-how to develop cutting-edge application security policies, conduct comprehensive security assessments throughout the SDLC, and seamlessly integrate security controls into web application development practices. Alongside conducting the training, I can also leverage my affinity for full SDLC support for new product features. Threat Modeling, Design Review, Manual Code Review, Exploit writing are tasks I am well-versed in performing and my awareness programs foster a culture of heightened security within teams. In all we do together, maximizing the productivity of your product security organization will remain a priority. From working with results of SAST/DAST tools and developing automation frameworks to support different security compliances to taking a holistic perspective on security risks; I prioritize both risk management and the realities on the ground. With every role I take on, I work meticulously to maintain the highest level of security integration possible while preserving smooth operations to promote your overall productivity. Let’s partner up to create an impregnable bastion against digital threats.
$140 USD 7 gün içinde
7,4
7,4

Hello there, I have extensive experience in application security, including secure software development, security testing tools like SAST, DAST, and IAST, and penetration testing using Qualys and Burp Suite. I am proficient in Java, Python, and JavaScript, and have led teams to integrate security into the SDLC with a focus on OWASP Top 10 vulnerabilities. My experience extends to cloud security, DevSecOps, and fostering security awareness across organizations. I can lead the design and implementation of application security policies, conduct security assessments, and provide training programs. I am skilled in threat modeling, secure coding, and vulnerability management, with a focus on cloud environments like AWS, Azure, and GCP. I also have hands-on experience with authentication and identity management best practices. Questions: • Are there specific compliance frameworks (e.g., FedRamp, PCI, HIPAA) you prioritize? • Do you need ongoing support for managing security incidents and response efforts? Looking forward to ensuring robust security practices aligned with industry standards. Thanks and best regards, Faizan
$90 USD 5 gün içinde
4,8
4,8

Hello There!!! ⚜️⭐⭐⭐⭐⚜️(( Delivering hands-on, advanced application security training aligned with real-world SDLC and cloud environments ))⚜️⭐⭐⭐⭐⚜️ This project immediately stood out because it focuses on practical, end-to-end application security training, covering secure development, threat modeling, vulnerability management, and cloud security practices. You are looking for someone who can guide teams through SDLC integration, testing methodologies, and hands-on exploit and mitigation exercises while fostering a culture of security awareness. I bring extensive experience in web and cloud security, secure coding practices in Python and Java, penetration testing with tools like Burp Suite and Qualys, and implementing DevSecOps processes. I focus on delivering actionable training that equips teams to identify, remediate, and prevent security vulnerabilities effectively. Key Features • Hands-on SDLC security support including threat modeling and code review • Practical cloud security and DevSecOps integration guidance • Vulnerability management and security assessment exercises I would be glad to discuss how I can structure sessions to ensure your team gains strong, applied security expertise. Warm Regards, Farhin B.
$156 USD 10 gün içinde
3,5
3,5

Hi, I am Haresh, having 14+ years of experience in Software Testing Industry. - Having unique blend of knowledge in Quality Product Delivery, Processes Management, Functional testing, Integration and regression testing, load and Perfromance Testing which help me to take the Quality of the software to the next level. - Hands on experience on testing Desktop, Web Based, Mobile application and ERP based application. - Hands on experience on automation testing tools on selenium webdriver, jmeter, katalon studio, Appium, cypress, selenium with TestNG freamwork etc.. - Thorough understanding of Product Delivery Life Cycle, Software Testing Life Cycle and Software Development Life Cycle. - Experience in Well conversant with writing Test plan,Test Cases,Bug report, Release Note and Product Health Report. - Worked in various domains like Finance, Retail, Web Portals, Healthcare, ecommnerce, CMS, Eduction Portal, Life Insurance, ERP system etc. - I do have require mobile devices to test mobile view or applications like android and iOS applications. - I have hands on experience with Git, postman, MSSQL Server. Kindly review my profile and let me know you view over the same. Thanks, Haresh
$240 USD 7 gün içinde
3,8
3,8

Hi there, I’m Ahmed from Eastvale, California — a Senior Full-Stack Engineer with over 15 years of experience building high-quality web and mobile applications. After reviewing your job posting, I’m confident that my background and skill set make me an excellent fit for your project — Advanced Application Security Training . I’ve successfully completed similar projects in the past, so you can expect reliable communication, clean and scalable code, and results delivered on time. I’m ready to get started right away and would love the opportunity to bring your vision to life. Looking forward to working with you. Best regards, Ahmed Hassan
$120 USD 2 gün içinde
2,9
2,9

When it comes to securing your applications, my experience and skillset are tailored-made for the job. With a deep understanding of secure software development practices and web application vulnerabilities, I am equipped to lead the design and implementation of comprehensive application security policies, best practices, and standards for your organization. My expertise includes using SAST, DAST, IAST solutions, and penetration testing tools like Qualys and Burp Suite to monitor and mitigate security risks in real time. Having worked with cloud-based systems like GCP, AWS, and Kubernetes, I am well-versed in containerization and DevSecOps practices, which allows me to integrate robust security controls into your entire software development lifecycle effectively. Beyond this, I maintain an up-to-date understanding of emerging threats, vulnerabilities, and industry trends ensuring that no blind-sides come your way. But my skills reach beyond just technical aptitude. Great communication is also vital when it comes to fostering a culture of security awareness within teams. Accredited with strong written and verbal skills, I'll be able to provide clear guidance on secure coding techniques and facilitate effective collaborations between cross-functional teams for risk-free project completion. Let me leverage my knowledgeand experience for the advancement of your application security training efforts.
$140 USD 5 gün içinde
2,0
2,0

Hi, hope you are doing well. I've read your proposal very carefully, and I am confident about my ability to meet your needs. I understand that you require a comprehensive approach to application security, with a focus on secure software development practices and vulnerability management. I have hands-on experience in application security, including expertise in OWASP Top 10 vulnerabilities, security testing tools like SAST and DAST, and cloud security practices. My approach includes: - Conducting thorough security assessments throughout the software development lifecycle. - Collaborating with development teams to integrate security best practices into their workflows. - Leading initiatives to foster a culture of security awareness across the organization. I can start immediately and complete the work within a short timeline. Looking forward to your reply.
$140 USD 7 gün içinde
0,0
0,0

Hello, I am a senior Japanese engineer for application security. I will help you implement strong security practices and mitigate vulnerabilities using my extensive experience in secure software development and application security assessments. I have successfully led teams to enhance system security, reducing vulnerabilities by over 30% in previous roles. My experience with tools like Qualys and Burp Suite allows for thorough security testing and effective penetration strategies. I collaborate closely with development teams to integrate best practices into the SDLC efficiently. I keep changes small and frequent so risk stays low. What is the most critical security policy or guideline you currently have in place? I am ready to begin and deliver steady results. Thank you. Taiga Fujita, Senior application security engineer.
$30 USD 3 gün içinde
0,0
0,0

With a wealth of experience in digital marketing, creative design and automation, I bring a unique perspective to your project - combining the highly technical expertise you need with an ability to translate that into practical, actionable terms that the people who most need it can understand. "Help develop and implement security processes to improve the overall productivity of the product security organization" - it's right there in your requirements, and I believe I bring that to the table. I am adept at condensing complex information into clear, concise instructions which have made my client's businesses thrive. My value lies in not only understanding these complex security features but also communicating them effectively. What good is expertise if it cannot be applied on-ground? As a bonus, I also have substantial knowledge in multi-tenant cloud environments (IaaS, SaaS, PaaS). As someone fully committed to personal growth and staying up-to-date with emerging services/vulnerabilities, I appreciate how critical it is in the ever-changing landscape of application security; I bring this same commitment to training my fellow teammates and stakeholders alike. My clients' needs are always changing - as are our solutions - and this capacity for rapid adaptation has served me well so far. Organi
$140 USD 7 gün içinde
0,0
0,0

Hello, As a seasoned software engineer with a penchant for intricate problem-solving, I'm confident that I possess the skills required to make a meaningful impact on your advanced application security training project. Not only do I boast over eight years of professional experience in C++ and Python development, but I also have ample knowledge in Java and web security – two key areas elucidated in your extensive project description. Moreover, my background in full-stack web development provides me a full 360-degree vision when it comes to application security. My proficiency encompasses secure software development practices and techniques, knowing how to detect and mitigate OWASP Top 10 vulnerabilities, as well as implementing security testing tools such as SAST, DAST, and IAST solutions. Lastly, your description hinted at familiarity with DevSecOps practices—a definite plus in my repertoire. My experience in AWS, Docker, CI/CD, Kubernetes proves that I understand cloud security, containerization, and the integration of robust security controls into the SDLC to develop fortified applications. In conclusion, if you're seeking an adept professional who prioritizes risk management perspective and can significantly enhance the overall productivity of your product security organization, I am ready to turn your project into a success! Thanks!
$170 USD 5 gün içinde
0,0
0,0

⭐Hi, I’m ready to assist you right away!⭐ I believe I’d be a great fit for your project since I have extensive experience in application security, including secure software development practices and techniques. With a strong understanding of web application security vulnerabilities and mitigation strategies like OWASP Top 10, I can ensure robust security measures for your applications. Additionally, my expertise in security testing tools, penetration testing, and knowledge of cloud security practices align well with your project requirements. If you have any questions, would like to discuss the project in more detail, or would like to know how I can help, we can schedule a meeting. Thank you. Maxim
$50 USD 5 gün içinde
0,0
0,0

Hi there, I am thrilled to propose my extensive expertise in application security to enhance your team's capabilities. With a robust background in software security practices, including OWASP Top 10 vulnerabilities and security testing tools like SAST, DAST, Qualys, and Burp Suite, I am well-equipped to lead the design and implementation of application security policies. My experience also extends to collaborating with development teams to integrate security controls and best practices throughout the SDLC, fostering a culture of security awareness, and conducting security assessments to mitigate vulnerabilities effectively. Additionally, I am well-versed in cloud security, DevSecOps practices, and secure coding techniques. I am eager to collaborate with your team to bolster your application security initiatives. Looking forward to discussing further details and addressing your questions. How do you envision integrating the latest security trends into your application development process?
$155 USD 2 gün içinde
0,0
0,0

Hello, I’ve read your project “Advanced Application Security Training” and understand what you’re aiming to achieve. I can deliver a clean, reliable result with clear communication and quick turnaround. https://www.freelancer.com/u/proggon Best regards, Wahaj Barlas
$140 USD 7 gün içinde
0,0
0,0

I’m applying for the Application Security position because it aligns directly with my experience securing large-scale, cloud-based applications and leading product security initiatives across the full SDLC. With strong proficiency in Python, Java and JavaScript, I combine hands-on secure coding skills with deep knowledge of OWASP, threat modeling, SDLC integration, and modern DevSecOps practices. I have led AppSec teams responsible for SAST/DAST/IAST programs, manual code reviews, exploit development, architectural design reviews, and continuous security automation. My experience includes building security policies, defining controls, training engineering teams, and collaborating closely with product, cloud and infrastructure groups. I routinely manage vulnerability triage, penetration testing cycles, bug bounty intake, and remediation workflows with a risk-based, business-aligned approach. I am highly familiar with securing multi-tenant architectures on AWS/Azure/GCP, implementing SSO/OIDC/SAML, validating third-party components, and ensuring compliance with frameworks such as PCI, HIPAA, and FedRamp. I also bring strong scripting, fuzzing, and exploit-analysis skills that help uncover complex issues early in design.
$240 USD 7 gün içinde
0,0
0,0

Hi there! Keeping applications secure is challenging, especially with evolving vulnerabilities and complex development environments. I understand how crucial practical, hands-on training is for your team’s security readiness. I can deliver advanced application security training covering secure coding, threat modeling, penetration testing, cloud security, and SDLC integration. Your team will learn actionable techniques to identify and mitigate risks, improve secure development practices, and handle real-world security challenges confidently. Do you want me to start with a gap analysis of your current team’s security skills? Open chat now to provide comprehensive application security training tailored for your development team.
$140 USD 7 gün içinde
0,0
0,0

Hi, I’m an experienced cybersecurity researcher and QA specialist with CVE credits (CVE-2019-13655, CVE-2020-8452, CVE-2022-26070) and three recognitions from NCIIPC. I’ve also served as a Cyber Security Adviser and earned acknowledgments from Google, Microsoft, and other major organizations. I bring strong technical skills, deep security expertise, and a sharp eye for identifying critical issues. I have extensive experience in application security, including secure development, architecture review, penetration testing, and vulnerability management. I work with SAST, DAST, IAST, CI/CD integrations, and manual testing using tools like Burp Suite, Qualys, and custom scripts. I also have hands-on experience in cloud security, container security, and DevSecOps. What I can do: • Security assessment across the SDLC • Static/dynamic analysis, code review, exploit development, fuzzing • Identify and mitigate web, mobile, cloud, and infra vulnerabilities • Integrate security controls into development workflows • Threat modeling, secure coding guidance, architecture review • Support incident and vulnerability response • Provide clear reports and actionable recommendations Additional strengths: • Strong knowledge of OWASP Top 10 and modern attack vectors • Proficient in Python, JavaScript, and security automation • Excellent communication and collaboration skills Ready to contribute immediately.
$290 USD 15 gün içinde
0,0
0,0

I am a Security Engineer with 6+ years of hands-on experience in application, cloud, and product security across enterprise and consulting environments. I have led end-to-end application security programs, covering secure design, threat modeling, penetration testing, vulnerability management, and incident response. I have strong expertise in OWASP Top 10, secure SDLC, and integrating SAST, DAST, and SCA tools into CI/CD pipelines. I regularly work with Burp Suite, Qualys, Semgrep, Checkmarx, Fortify, and Snyk, validating findings, eliminating false positives, and driving remediation with engineering teams. My experience includes manual and automated pentesting across web, API, mobile, cloud, and containerized environments, along with exploit writing, adversarial testing, and security automation. I am proficient in Python, Java, and JavaScript, and routinely perform manual code reviews, secure design reviews, and threat modeling using architecture and data flow diagrams. I have worked extensively with AWS, Azure, and GCP, securing IAM, authentication/SSO (SAML, OIDC, OAuth2, SCIM), containers, and multi-tenant SaaS/PaaS architectures. I’ve supported security audits, bug bounty programs, and compliance efforts such as PCI DSS and HIPAA, with exposure to FedRAMP-aligned controls. I’ve also mentored AppSec engineers, defined security standards, partnered closely with product teams, and prioritized risks using a practical, business-driven approach
$170 USD 10 gün içinde
0,0
0,0

Our background makes us well-suited to handle this project effectively, I’ve successfully delivered work comparable to what you need. Understanding your focus on secure software development practices and the necessity for seamless integration of security testing tools such as SAST, DAST, and IAST, we recognize the importance of a clean, professional, and user-friendly approach to application security that is both automated and integrated throughout the SDLC. We offer expertise in application security architecture, threat modeling, and security automation frameworks, with strong proficiency in Python, Java, and JavaScript. While our company is new to the freelancer platform we are not new to the industry, we have a wide range of experience and expertise in cloud security, penetration testing, and DevSecOps practices to ensure robust, risk-managed security solutions are delivered. I’m available to discuss the project in more detail whenever you are ready. Regards, Lerikus
$100 USD 14 gün içinde
0,0
0,0

Hello Sir/Madam, I trust that this message reaches you well. I am a Web Penetration Tester with good knowledge in Mobile Testing and Web Development. I focus on Testing Web and Mobile Applications using the structure of the OWASP TOP TEN. I feel the requirements for your project should be split to avoid contract issues like timely delivery and efficient service. I have the great experience in Cybersecurity and average in Web development but I'll be glad to offer my expertise in Web and Mobile Security. Thanks for considering my request. I'm open for price and time negotiations.
$40 USD 7 gün içinde
0,0
0,0

Frisco, United States
Ara 11, 2025 tarihinden bu yana üye
$30-250 USD
$10-30 USD
minimum £36 GBP / saat
₹12500-37500 INR
£18-36 GBP / saat
$500-1000 USD
₹600-1500 INR
$1500-3000 USD
€750-1500 EUR
$30-250 USD
minimum £36 GBP / saat
₹600-1500 INR
$15-25 USD / saat
$10-30 USD
$30-250 USD
$250-750 USD
₹600-1500 INR
$10-30 USD
$10-30 AUD
€250-750 EUR
$10-30 USD