Senior Application Security Consultant, Strategic Services- Remote (Anywhere in the U.S.)

1 month, 2 weeks ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Deliver application security services, including application threat modeling, application architecture reviews, and AppSec/DevSecOps program assessments.
  • Author comprehensive assessment deliverables for technical and managerial audiences, covering execution, deficiencies, business impact, and remediation strategies.
  • Communicate directly with clients, manage concurrent engagements, and provide support, information, and guidance.
  • Provide remediation guidance based on identified application security issues and mitigation strategies.
  • Analyze complex application architectures and assess security controls, requirements, and standards.
  • Work with development teams to integrate security into the SDLC and support secure implementation practices.
  • Assist with practice development by improving offerings and mentoring team members.
  • Contribute to marketing initiatives through research, speaking, writing, and tool development.
  • Foster strong client relationships while supporting ongoing engagements.
  • Embrace and apply emerging technologies, including AI tools, to improve workflows and business outcomes.

Requirements

  • Willingness to travel up to 10%.
  • 6+ years of experience in Application Security and/or Software Development, including at least 3 years in Application Security.
  • At least 2 years of experience in consulting services or internal security roles requiring communication with both technical teams and executive leadership.
  • Hands-on experience delivering application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments.
  • Strong understanding of application security tools, methodologies, and frameworks such as OWASP SAMM, OWASP DSOMM, NIST SSDF, SLSA, NIST AI RMF, and MITRE ATLAS.
  • Deep knowledge of application security issues, mitigation strategies, and common security controls.
  • Experience working within development teams and integrating security into the SDLC.
  • Development or application architecture background with secure implementation knowledge for cryptography, input validation, injection prevention, and exception management.
  • Operational DevSecOps experience.
  • Programming experience in JavaScript, shell, Python, Java, C++, PHP, or C#, with the ability to translate security requirements into technical implementations.
  • Excellent writing, communication, and time management skills.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • Comprehensive hands-on experience using generative AI in automated workflows.
  • Experience with application security controls, architectures, requirements, and industry standards.
  • Startup mentality with a highly driven, high-performance approach to work.
  • Experience using Greenhouse Software and Zoom Scheduler is implied by the hiring process.

Benefits

  • Remote-first work environment for U.S.-based employees, with some roles requiring travel or on-site work for Federal positions.
  • Group medical insurance options, including a Zero Deductible PPO plan and a High Deductible Health Plan with HSA contributions.
  • Group dental insurance with 100% employer-paid employee premium and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for the retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
16 hours, 18 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
17 hours, 3 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 16 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 17 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers