Senior Application Security Consultant, Strategic Services- Remote (Anywhere in the U.S.)

2 months, 4 weeks ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Deliver application security services, including application threat modeling, application architecture reviews, and AppSec/DevSecOps program assessments.
  • Author comprehensive assessment deliverables for technical and managerial audiences, covering execution, deficiencies, business impact, and remediation strategies.
  • Communicate directly with clients, manage concurrent engagements, and provide support, information, and guidance.
  • Provide remediation guidance based on identified application security issues and mitigation strategies.
  • Analyze complex application architectures and assess security controls, requirements, and standards.
  • Work with development teams to integrate security into the SDLC and support secure implementation practices.
  • Assist with practice development by improving offerings and mentoring team members.
  • Contribute to marketing initiatives through research, speaking, writing, and tool development.
  • Foster strong client relationships while supporting ongoing engagements.
  • Embrace and apply emerging technologies, including AI tools, to improve workflows and business outcomes.

Requirements

  • Willingness to travel up to 10%.
  • 6+ years of experience in Application Security and/or Software Development, including at least 3 years in Application Security.
  • At least 2 years of experience in consulting services or internal security roles requiring communication with both technical teams and executive leadership.
  • Hands-on experience delivering application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments.
  • Strong understanding of application security tools, methodologies, and frameworks such as OWASP SAMM, OWASP DSOMM, NIST SSDF, SLSA, NIST AI RMF, and MITRE ATLAS.
  • Deep knowledge of application security issues, mitigation strategies, and common security controls.
  • Experience working within development teams and integrating security into the SDLC.
  • Development or application architecture background with secure implementation knowledge for cryptography, input validation, injection prevention, and exception management.
  • Operational DevSecOps experience.
  • Programming experience in JavaScript, shell, Python, Java, C++, PHP, or C#, with the ability to translate security requirements into technical implementations.
  • Excellent writing, communication, and time management skills.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • Comprehensive hands-on experience using generative AI in automated workflows.
  • Experience with application security controls, architectures, requirements, and industry standards.
  • Startup mentality with a highly driven, high-performance approach to work.
  • Experience using Greenhouse Software and Zoom Scheduler is implied by the hiring process.

Benefits

  • Remote-first work environment for U.S.-based employees, with some roles requiring travel or on-site work for Federal positions.
  • Group medical insurance options, including a Zero Deductible PPO plan and a High Deductible Health Plan with HSA contributions.
  • Group dental insurance with 100% employer-paid employee premium and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for the retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Mobile Software Engineer (iOS / Android), Identity & Security - India

JumpCloud 251-1K Internet Software & Services

JumpCloud is hiring a Senior Mobile Software Engineer to build secure native iOS and Android applications that protect enterprise identities through authentication, password management, and identity verification.

Android AWS CI/CD Encryption Espresso GCP GitHub Actions Go iOS Kotlin OpenID Connect REST API Swift WebSockets XCTest
2 hours, 8 minutes ago

Staff Application Security Engineer (R5949)

Bitly 51-250 Internet Software & Services

Shield AI is seeking a Staff Application Security Engineer to establish and scale a developer-centered secure software development and software supply-chain security program across its defense-technology engineering organization.

Burp Suite DevSecOps Kubernetes Microservices SonarQube
2 hours, 38 minutes ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
1 day, 1 hour ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
1 day, 2 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers