
Lead Strategic Services Consultant – Application Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Massachusetts.
• Support clients with the configuration of application security testing (AST) tools within their pipelines by creating templates and verifying settings.
• Offer triage assistance to clients regarding AST findings from their pipeline evaluations.
• Conduct AppSec Program maturity evaluations using frameworks like BSIMM and SSDF, which include stakeholder interviews, evidence gathering, and scoring.
• Create Strategic Roadmaps that outline the client’s desired future state, a 12–36-month action plan, resource needs, and success metrics.
• Lead workshops with executives, engineering teams, and AppSec leadership to prioritize initiatives and ensure alignment with organizational risk and compliance objectives.
• Present strategic recommendations to CISOs, CTOs, and leadership teams in software development.
• Assist in the development of internal frameworks, templates, and accelerators, including AppSec Program Roadmap intellectual property, maturity scoring tools, and reporting dashboards.
• Engage in thought leadership by participating in press commentary, webinars, or presenting at conferences focused on secure software governance and maturity enhancement.
• Provide hands-on support for DevSecOps and CI/CD operations, including AppSec Program Roadmap plans and assessments, framework reports and presentations, capability maturity visuals, and strategic recommendations for executive-level engagements.
• Must be a US citizen or Green Card holder with 3 years of residency in the US and the ability to pass a background check.
• 5–8+ years of experience in application security, software assurance, or product security consulting.
• Proficient in Application Security and Vulnerability Management.
• Experience with GitLab CI/CD, Python, AWS, and Grafana.
• Familiarity with BSIMM, NIST SSDF, or OWASP SAMM frameworks.
• Demonstrated experience in developing or implementing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps initiatives.
• Strong client-facing communication, facilitation, and presentation skills.
• Ability to distill technical findings into executive-level narratives and actionable strategies.
• Preferred: consulting background with a Big Four firm, a specialized AppSec consultancy, or an internal software security governance team.
• Preferred: experience in software supply chain risk management, AI/ML assurance, or DevSecOps pipeline architecture.
• Preferred: experience in software development and operating within secure development lifecycles.
• Preferred: industry certifications such as CEH, CISSP, or CISM.
• Comprehensive health insurance options.
• Generous paid time off policy.
• Professional development opportunities.
• Flexible work arrangements.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.