Security Consultant – Penetration Testing, DevSecOps

Posted Sep 16

This is a fully remote position, open to applicants in Alabama, +18 more states.

📋 Description

• Conduct both manual and automated penetration testing for web applications, APIs, mobile applications, cloud environments, and related infrastructure.

• Carry out reconnaissance, vulnerability identification, exploitation, and post-exploitation tasks utilizing OWASP, PTES, NIST, and MITRE ATT&CK frameworks.

• Detect vulnerabilities, confirm exploitability, evaluate business risks, and offer actionable remediation suggestions.

• Perform security assessments on microservices, containers, Kubernetes, and cloud-native applications.

• Create proof-of-concept demonstrations that highlight security flaws and attack vectors.

• Generate comprehensive technical reports and executive summaries for clients and stakeholders.

• Incorporate security controls and testing within CI/CD pipelines.

• Deploy and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions.

• Collaborate with development teams to address vulnerabilities and promote secure coding practices.

• Engage in security architecture reviews, threat modeling sessions, and secure design evaluations.

• Automate security testing and compliance verification across DevOps toolchains.

• Establish security guardrails and policy-as-code functionalities.

• Conduct vulnerability triage, risk prioritization, and remediation monitoring.

• Assist with ongoing security monitoring and risk assessment initiatives.

• Examine emerging threats, attack strategies, and security developments.

• Contribute to the formulation of security standards, procedures, and best practices.

• Collaborate with engineering, cloud, and infrastructure teams to enhance the organization's security posture.

• Present findings and recommendations to developers, architects, engineering teams, and leadership personnel.

• Provide security consulting throughout the entire software development lifecycle.


⛳️ Requirements

• A Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline.

• 5-8 years of practical experience in cybersecurity.

• At least 3+ years of experience in application and API penetration testing.

• Proven experience in implementing or supporting DevSecOps initiatives within CI/CD environments.

• Strong knowledge of Web Application Security, API Security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, Threat Modeling, and Vulnerability Management.

• Hands-on experience with tools such as Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins.

• Possession of one or more recognized security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty.

• Experience in container security (Docker, Kubernetes).

• Experience in conducting cloud penetration tests.

• Familiarity with Infrastructure as Code (Terraform, CloudFormation).

• Understanding of Red Team methodologies and adversary simulation.

• Knowledge of Zero Trust Architecture and Secure-by-Design principles.

• Experience with AI/LLM security testing is an advantage.

• Strong communication, consulting, and stakeholder management abilities.


🏝️ Benefits

• Vacation: 12-25 days, depending on grade.

• Company-paid holidays.

• Personal Days.

• Sick Leave.

• Medical, dental, and vision coverage (or provincial healthcare coordination in Canada).

• Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada).

• Life and disability insurance.

• Employee assistance programs.

• Additional benefits as outlined by local policy and eligibility.

• Potential for variable incentives, bonuses, or commissions.

People also viewed

Horizon3.ai1 day ago

Staff Site Reliability Engineer

US flagUnited States OnlyFull-timeDevOps & Site Reliability Engineer (SRE)$199.8k – $270k/year
ApplyView job
CLOUD MANTA GmbH1 day ago

Senior DevOps Engineer, Containers & Private Cloud

DE flagGermany OnlyFull-timeDevOps & Site Reliability Engineer (SRE)€70k – €80k/year
ApplyView job
Stefanini LATAM1 day ago

Senior DevOps

AR flagArgentina OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
Akamai Technologies1 day ago

Principal Site Reliability Engineer – Lead

PL flagPoland OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

DevSecOps Engineer

US flagAlabama, +1 more stateFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
Ad Hoc LLC1 day ago

Staff DevOps Engineer

US flagUnited States OnlyFull-timeDevOps & Site Reliability Engineer (SRE)$130k – $150k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers