
Security Consultant – Penetration Testing, DevSecOps
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in Alabama, +18 more states.
• Conduct both manual and automated penetration testing for web applications, APIs, mobile applications, cloud environments, and related infrastructure.
• Carry out reconnaissance, vulnerability identification, exploitation, and post-exploitation tasks utilizing OWASP, PTES, NIST, and MITRE ATT&CK frameworks.
• Detect vulnerabilities, confirm exploitability, evaluate business risks, and offer actionable remediation suggestions.
• Perform security assessments on microservices, containers, Kubernetes, and cloud-native applications.
• Create proof-of-concept demonstrations that highlight security flaws and attack vectors.
• Generate comprehensive technical reports and executive summaries for clients and stakeholders.
• Incorporate security controls and testing within CI/CD pipelines.
• Deploy and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions.
• Collaborate with development teams to address vulnerabilities and promote secure coding practices.
• Engage in security architecture reviews, threat modeling sessions, and secure design evaluations.
• Automate security testing and compliance verification across DevOps toolchains.
• Establish security guardrails and policy-as-code functionalities.
• Conduct vulnerability triage, risk prioritization, and remediation monitoring.
• Assist with ongoing security monitoring and risk assessment initiatives.
• Examine emerging threats, attack strategies, and security developments.
• Contribute to the formulation of security standards, procedures, and best practices.
• Collaborate with engineering, cloud, and infrastructure teams to enhance the organization's security posture.
• Present findings and recommendations to developers, architects, engineering teams, and leadership personnel.
• Provide security consulting throughout the entire software development lifecycle.
• A Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline.
• 5-8 years of practical experience in cybersecurity.
• At least 3+ years of experience in application and API penetration testing.
• Proven experience in implementing or supporting DevSecOps initiatives within CI/CD environments.
• Strong knowledge of Web Application Security, API Security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, Threat Modeling, and Vulnerability Management.
• Hands-on experience with tools such as Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins.
• Possession of one or more recognized security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty.
• Experience in container security (Docker, Kubernetes).
• Experience in conducting cloud penetration tests.
• Familiarity with Infrastructure as Code (Terraform, CloudFormation).
• Understanding of Red Team methodologies and adversary simulation.
• Knowledge of Zero Trust Architecture and Secure-by-Design principles.
• Experience with AI/LLM security testing is an advantage.
• Strong communication, consulting, and stakeholder management abilities.
• Vacation: 12-25 days, depending on grade.
• Company-paid holidays.
• Personal Days.
• Sick Leave.
• Medical, dental, and vision coverage (or provincial healthcare coordination in Canada).
• Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada).
• Life and disability insurance.
• Employee assistance programs.
• Additional benefits as outlined by local policy and eligibility.
• Potential for variable incentives, bonuses, or commissions.
Horizon3.ai
CLOUD MANTA GmbH
Stefanini LATAM
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.