
Application Security Consultant
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in United States.
• Provide Application Security services, which include evaluations for web, mobile, AI, and thick client applications, Threat Modeling, and Source Code Reviews.
• Conduct AI/LLM and Agentic Application Security Evaluations, addressing prompt injection, model/guardrail bypass, excessive agency abuse, tool-calling exploitation, RAG poisoning, and various OWASP-mapped threats.
• Evaluate agentic AI architectures such as LangChain, CrewAI, AutoGPT, MCP-based agents, and Salesforce Agentforce.
• Create assessment deliverables aimed at both technical and managerial audiences, outlining technical execution, deficiencies, business impact, and remediation strategies.
• Develop and enhance AI-driven tools, custom agents, agent capabilities, tool integrations, and automation frameworks for security assessments.
• Leverage automation, orchestration, scripting, and AI-assisted tools to enhance efficiency and enable new client functionalities.
• Contribute to Application Security research, particularly in emerging AI and agentic threat domains.
• Assist marketing efforts through conference presentations, writing blogs and whitepapers, conducting webinars, and contributing to security tools.
• Cultivate client relationships while providing support and information.
• Stay updated on information security, AI/LLM, and agentic security knowledge; share insights with team members and help shape the future of the Practice.
• High School Diploma plus 5 years of experience OR Bachelor’s Degree (BS/BA) plus 2 years of experience OR Master’s Degree (MS/MA).
• At least two (2) years of experience in conducting Application Security assessments.
• A minimum of one (1) year of experience in an enterprise-level consulting services position.
• Proficiency with testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, OpenSSL, and others.
• Experience in reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#.
• Practical experience in testing AI/LLM-powered applications and agentic AI systems for prompt injection, data leakage, excessive agency, insecure output handling, and tool/function-calling exploitation.
• Familiarity with the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, along with hands-on testing experience.
• General fluency in AI and its practical applications, including LLM APIs/SDKs such as OpenAI, Anthropic, Bedrock, and Azure OpenAI.
• Capability to utilize emerging AI technologies to solve problems and achieve business objectives.
• Willingness to travel up to 20%.
• Ability to perform sedentary work; significant wrist, hand, and/or finger movement for a minimum of 8 hours daily; close visual acuity for computer terminal usage and/or extensive reading for at least 8 hours daily.
• Primarily remote workforce (U.S. based only).
• Group Medical Insurance options: Zero Deductible PPO Plan with GuidePoint covering 90% of the employee premium and 70% of family premiums.
• High Deductible Health Plan with HSA; GuidePoint pays 100% of employee premiums and 75% of family premiums.
• HSA contribution of $850 annually for employees or $1,750 annually for families.
• Group Dental Insurance with GuidePoint covering 100% of employee premiums and 75% of family premiums.
• 12 corporate holidays.
• Flexible Time Off (FTO) program.
• Healthy mobile phone and home internet allowance.
• Eligibility for retirement plan after 2 months during open enrollment.
• Pet Benefit Option.
• Mentorship and guidance from experienced colleagues.
Zscaler
Viatris
ActBlue
AlphaSense
Get handpicked remote jobs straight to your inbox weekly.