Senior Application Security Consultant, Strategic Services- Remote (Anywhere in the U.S.)

4 weeks ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Deliver application security services, including application threat modeling, application architecture reviews, and AppSec/DevSecOps program assessments.
  • Author comprehensive assessment deliverables for technical and managerial audiences, covering execution, deficiencies, business impact, and remediation strategies.
  • Communicate directly with clients, manage concurrent engagements, and provide support, information, and guidance.
  • Provide remediation guidance based on identified application security issues and mitigation strategies.
  • Analyze complex application architectures and assess security controls, requirements, and standards.
  • Work with development teams to integrate security into the SDLC and support secure implementation practices.
  • Assist with practice development by improving offerings and mentoring team members.
  • Contribute to marketing initiatives through research, speaking, writing, and tool development.
  • Foster strong client relationships while supporting ongoing engagements.
  • Embrace and apply emerging technologies, including AI tools, to improve workflows and business outcomes.

Requirements

  • Willingness to travel up to 10%.
  • 6+ years of experience in Application Security and/or Software Development, including at least 3 years in Application Security.
  • At least 2 years of experience in consulting services or internal security roles requiring communication with both technical teams and executive leadership.
  • Hands-on experience delivering application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments.
  • Strong understanding of application security tools, methodologies, and frameworks such as OWASP SAMM, OWASP DSOMM, NIST SSDF, SLSA, NIST AI RMF, and MITRE ATLAS.
  • Deep knowledge of application security issues, mitigation strategies, and common security controls.
  • Experience working within development teams and integrating security into the SDLC.
  • Development or application architecture background with secure implementation knowledge for cryptography, input validation, injection prevention, and exception management.
  • Operational DevSecOps experience.
  • Programming experience in JavaScript, shell, Python, Java, C++, PHP, or C#, with the ability to translate security requirements into technical implementations.
  • Excellent writing, communication, and time management skills.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • Comprehensive hands-on experience using generative AI in automated workflows.
  • Experience with application security controls, architectures, requirements, and industry standards.
  • Startup mentality with a highly driven, high-performance approach to work.
  • Experience using Greenhouse Software and Zoom Scheduler is implied by the hiring process.

Benefits

  • Remote-first work environment for U.S.-based employees, with some roles requiring travel or on-site work for Federal positions.
  • Group medical insurance options, including a Zero Deductible PPO plan and a High Deductible Health Plan with HSA contributions.
  • Group dental insurance with 100% employer-paid employee premium and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for the retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevSecOps

Cato Networks 251-1K Diversified Telecommunication Services

Cato Networks is hiring an Application Security Engineer (DevSecOps) to embed security across its cloud-based software development lifecycle and help R&D teams deliver secure applications at scale.

Agile AWS CI/CD DevSecOps Docker Go Java Kubernetes Microservices Network Security Python Terraform
1 day, 12 hours ago

Manager, Product Research

Huntress 251-1K Professional Services

Huntress is hiring a remote US Product Research Manager to lead cybersecurity research efforts that improve threat detection and prevention for customers.

Cybersecurity
4 days, 14 hours ago

Lead Application Security Engineer

Zeta Global 1K-5K Media

Zeta Global is hiring a Lead Application Security Engineer to strengthen application and platform security across its AI-powered marketing platforms through automated, AI-native security practices and cross-functional security engineering.

AWS Azure Burp Suite CI/CD Cybersecurity DevSecOps Django Docker FastAPI GCP JWT Kubernetes Microservices Node.js OAuth OpenID Connect React SonarQube
5 days, 12 hours ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architecture IC to define and drive secure-by-design architecture across its enterprise planning platform and AI products.

Encryption Machine Learning OWASP
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers