
Senior Application Security Consultant, Strategic Services
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
• Provide these services to clients across different sectors
• Become a part of GuidePoint’s distinguished team to conduct engagements, interact with clients, produce detailed reports, and offer remediation advice
• Play a role in enhancing our service offerings to address emerging threats and client requirements
• Openness to travel up to 10%
• Providing Application Security services, which include Application Threat Modeling, Application Architecture Reviews, and AppSec/DevSecOps Program Assessments
• Create thorough assessment deliverables aimed at both technical and managerial audiences, outlining technical execution, deficiencies, business impact, and remediation strategies
• Familiarity with the application security landscape, tools, methodologies, and frameworks such as OWASP SAMM, OWASP DSOMM, NIST SSDF, SLSA, NIST AI RMF, and MITRE ATLAS
• In-depth understanding of application security challenges, mitigation techniques, and common security controls
• Capability to analyze and comprehend intricate application architectures
• Experience collaborating directly with development teams and embedding security within the SDLC
• Support Practice development, enhance offerings, and mentor team members
• Contribute to marketing efforts through research, speaking engagements, writing, and tool creation
• Build and maintain client relationships through support, information sharing, and guidance while managing multiple client engagements
• Exhibits a startup mindset with a highly motivated, high-performance work ethic
• Adopts emerging technologies, including AI tools, to enhance efficiency, solve problems, and achieve superior business results
• Extensive hands-on experience utilizing generative AI in automated workflows
• Direct hands-on experience in application security services, such as application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments
• Familiarity with application security controls, architectures, requirements, and industry standards
• Background in development and/or application architecture design with knowledge of secure implementation practices for cryptography, input validation methods to prevent injection attacks, and exception management
• Operational experience in DevSecOps
• Development experience in languages like JavaScript, shell, Python, Java, C++, PHP, or C#, with the ability to translate security requirements into technical implementations
• Strong writing, communication, and time management skills
• At least 6 years of experience in Application Security and/or Software Development, with a minimum of 3 years specifically in Application Security
• At least 2 years of experience in consulting services or internal security roles that require effective communication with both technical teams and executive leadership
• Bachelor’s degree in a relevant field or equivalent experience.
• Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint covers 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of employee premiums and 75% for family plans (spouse/children/family). If you opt for the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
• Group Dental Insurance: GuidePoint covers 100% of the premium for employees and 75% for family plans
• 12 corporate holidays and a Flexible Time Off (FTO) program
• Healthy mobile phone and home internet allowance
• Eligibility for retirement plan after 2 months at open enrollment
• Pet Benefit Option
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.