Senior Application Security Consultant, Strategic Services- Remote (Anywhere in the U.S.)

2 months, 1 week ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Deliver application security services, including application threat modeling, application architecture reviews, and AppSec/DevSecOps program assessments.
  • Author comprehensive assessment deliverables for technical and managerial audiences, covering execution, deficiencies, business impact, and remediation strategies.
  • Communicate directly with clients, manage concurrent engagements, and provide support, information, and guidance.
  • Provide remediation guidance based on identified application security issues and mitigation strategies.
  • Analyze complex application architectures and assess security controls, requirements, and standards.
  • Work with development teams to integrate security into the SDLC and support secure implementation practices.
  • Assist with practice development by improving offerings and mentoring team members.
  • Contribute to marketing initiatives through research, speaking, writing, and tool development.
  • Foster strong client relationships while supporting ongoing engagements.
  • Embrace and apply emerging technologies, including AI tools, to improve workflows and business outcomes.

Requirements

  • Willingness to travel up to 10%.
  • 6+ years of experience in Application Security and/or Software Development, including at least 3 years in Application Security.
  • At least 2 years of experience in consulting services or internal security roles requiring communication with both technical teams and executive leadership.
  • Hands-on experience delivering application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments.
  • Strong understanding of application security tools, methodologies, and frameworks such as OWASP SAMM, OWASP DSOMM, NIST SSDF, SLSA, NIST AI RMF, and MITRE ATLAS.
  • Deep knowledge of application security issues, mitigation strategies, and common security controls.
  • Experience working within development teams and integrating security into the SDLC.
  • Development or application architecture background with secure implementation knowledge for cryptography, input validation, injection prevention, and exception management.
  • Operational DevSecOps experience.
  • Programming experience in JavaScript, shell, Python, Java, C++, PHP, or C#, with the ability to translate security requirements into technical implementations.
  • Excellent writing, communication, and time management skills.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • Comprehensive hands-on experience using generative AI in automated workflows.
  • Experience with application security controls, architectures, requirements, and industry standards.
  • Startup mentality with a highly driven, high-performance approach to work.
  • Experience using Greenhouse Software and Zoom Scheduler is implied by the hiring process.

Benefits

  • Remote-first work environment for U.S.-based employees, with some roles requiring travel or on-site work for Federal positions.
  • Group medical insurance options, including a Zero Deductible PPO plan and a High Deductible Health Plan with HSA contributions.
  • Group dental insurance with 100% employer-paid employee premium and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for the retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
2 days, 16 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
2 days, 17 hours ago

Lead Application Security Engineer

Remofirst 11-50 Professional Services

RemoFirst is hiring an application and cloud security engineer to secure its global Employer of Record platform, customer identity systems, infrastructure, and emerging AI initiatives across a distributed engineering organization.

AWS Django FastAPI Java Kafka Kubernetes MongoDB OpenID Connect Penetration Testing PostgreSQL Python RabbitMQ REST API SAML Secrets Management Spring Boot Terraform
2 days, 17 hours ago

Application Security Engineer II

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring an Application Security Engineer to triage and validate vulnerability submissions for major clients, communicate with researchers and customers, and support incident response across diverse security programs.

Burp Suite Nmap
3 days, 17 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers