We help organizations make smarter cybersecurity decisions that minimize risk.
Senior Application Security Consultant, Strategic Services
Location
United States
Posted
4 days ago
Salary
0
Seniority
Senior
Job Description
Senior Application Security Consultant, Strategic Services
GuidePoint Security
• Deliver these offerings to clients across various industries • Join GuidePoint’s elite team to perform engagements, communicate with clients, deliver comprehensive reports, and provide remediation guidance • Contribute to evolving our service offerings in response to emerging threats and client needs
Job Requirements
- Willingness to travel up to 10%
- Delivering Application Security services, including Application Threat Modeling, Application Architecture Reviews, and AppSec/DevSecOps Program Assessments
- Author comprehensive assessment deliverables tailored to both technical and managerial audiences detailing technical execution, deficiencies, business impact, and remediation strategies
- Understanding of application security landscape, tools, methodologies, and frameworks such as OWASP SAMM, OWASP DSOMM, NIST SSDF, SLSA, NIST AI RMF, and MITRE ATLAS
- Deep understanding of application security issues, mitigation strategies, and common security controls
- Ability to analyze and understand complex application architectures
- Experience working directly within development teams and integrating security into the SDLC
- Assist with Practice development, improving offerings, and mentoring team members
- Contribute to marketing initiatives via research, speaking, writing, and tool development
- Foster client relationships through support, information, and guidance while managing concurrent client engagements
- Demonstrates a startup mentality with a highly driven, high-performance approach to work
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- Comprehensive hands-on experience using generative AI in automated workflows
- Direct hands-on experience in application security service offerings, including application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments
- Experience with application security controls, architectures, requirements, and industry standards
- Development and/or application architecture design background with understanding of secure implementation practices for cryptography, input validation techniques to prevent injection attacks, and exception management
- Operational DevSecOps experience
- Development experience in JavaScript, shell, Python, Java, C++, PHP, or C#, with ability to translate security requirements into technical implementations
- Excellent writing, communication, and time management skills
- Minimum of 6 years of experience in Application Security and/or Software Development, with at least 3 years in Application Security
- Minimum of 2 years of experience in consulting services or internal security roles requiring effective communication with both technical teams and executive leadership
- Bachelor’s degree in a relevant discipline or equivalent experience.
Benefits
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
AI Security Engineer
AspenView Technology PartnersAspenView Technology Partners empowers organizations to thrive with agile, expert-staffed, nearshore IT teams.
Role Description Establish and operationalize security controls for emerging Artificial Intelligence and Machine Learning capabilities across the enterprise. This role is responsible for embedding security into AI solution design, protecting AI models and data pipelines, and enabling secure adoption of AI use cases across business and technology functions. The role works closely with Digital, Data, AI, Security Architecture, Engineering, and Cyber Defense Operations teams to define secure AI architecture patterns, implement guardrails, and ensure AI platforms operate within client’s cybersecurity, risk, and governance standards. The ideal candidate combines strong cybersecurity engineering capability with practical knowledge of AI platforms, model risks, and enterprise technology integration. What you will do: - AI Security Architecture & Engineering - Define secure architecture patterns for AI and machine learning solutions, ensuring protection of models, training pipelines, inference environments, and supporting data flows. - Establish secure integration patterns for AI services across enterprise applications, APIs, cloud platforms, and data environments. - Review AI solution designs to ensure alignment with enterprise security architecture standards and secure-by-design principles. - Support implementation of secure controls across AI development, testing, deployment, and production environments. - AI Risk Management & Security Controls - Identify, assess, and mitigate AI-specific threats including model poisoning, prompt injection, adversarial attacks, unauthorized model access, data leakage, and misuse of AI outputs. - Define and implement security guardrails for AI model access, API usage, prompt controls, and secure interaction with enterprise data sources. - Establish controls to protect sensitive training data, embeddings, prompts, and inference outputs across AI workflows. - Support validation of third-party AI services and external model integrations from a cybersecurity risk perspective. - Governance, Standards & Responsible AI Enablement - Establish AI security standards, engineering guardrails, and governance practices aligned with regulatory requirements, enterprise risk expectations, and responsible AI principles. - Partner with Digital and AI teams to enable secure AI use cases where security accelerates responsible business adoption rather than acts as a blocker. - Support creation of AI security review checkpoints for new AI initiatives, pilots, and production deployments. - Contribute to enterprise AI security policies, reference architectures, and operational standards. - Operational Security & Monitoring - Collaborate with Cyber Defense Operations to operationalize AI-related detection, monitoring, and response capabilities. - Support development of monitoring use cases for AI misuse, abnormal model behavior, unauthorized access, and suspicious data movement. - Define logging and telemetry requirements for AI platforms to improve visibility and incident readiness. - Support integration of AI platform telemetry into enterprise detection and monitoring tools where applicable. - Cross-Functional Collaboration - Work closely with Security Architecture, Cloud Engineering, Data teams, Application teams, and AI program owners to ensure consistent security adoption. - Support security reviews for AI vendors, AI-enabled SaaS platforms, and internally developed AI capabilities. - Provide technical guidance to project teams on secure AI implementation and operational controls. Qualifications - 5–8 years of cybersecurity engineering or security architecture experience, with exposure to cloud security, data protection, or application security. - Experience working with enterprise AI, machine learning, analytics platforms, or data-driven technology environments. - Practical understanding of AI/ML deployment patterns, APIs, model lifecycle, and enterprise data integration. - Experience with Microsoft Azure AI services, OpenAI integrations, Databricks, or enterprise AI platforms preferred. - Familiarity with emerging AI governance frameworks and responsible AI standards. - Experience with Secure AI controls embedded into enterprise AI initiatives without slowing adoption. - Clear visibility into AI-related cyber risks and mitigation actions and ability to translate emerging AI risks into practical engineering controls. - Practical AI guardrails established for data, model access, and operational use. - Strong alignment between AI innovation, enterprise security, and regulatory expectations. - Security certifications such as CISSP, CCSP, or cloud security certifications preferred. Security Engineering Skills - Strong understanding of cybersecurity controls across cloud, applications, APIs, identity, and data protection. - Familiarity with AI/ML risks including prompt injection, model abuse, data leakage, and adversarial techniques. - Knowledge of secure architecture principles for modern digital and AI platforms. Equal Opportunity Employer AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.
Sr Product Security Engineer
BeyondTrustProtect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.
Role Description We're hiring a Sr Product Security Engineer to do deep, hands-on security testing across BeyondTrust's product portfolio using AI as a force multiplier. You'll use Claude, Codex, and LLM-driven workflows to build threat hunting skills, develop fuzz factory plugins, and perform context-rich penetration testing that goes beyond what scanners and checklists catch. This is a technical role. You'll discover vulnerabilities, build proof-of-concept exploits, validate findings, and work with engineering to remediate them. You'll also partner closely with Security Architects and Cyber Defense to turn offensive findings into defensive mechanisms: detection signatures, monitoring rules, and hardening guidance informed by real exploitation paths you've validated firsthand. Our Product Security organization operates AI-first. You'll leverage Claude and Codex daily to automate repetitive testing workflows, generate targeted fuzz inputs, build custom security tooling, analyze code paths at scale, and produce exploit PoCs faster than manual methods allow. You'll also contribute back to the team by building reusable skills, prompts, and plugins that make everyone's testing more effective. What You’ll Do - AI-Driven Security Testing & Vulnerability Discovery: - Perform deep, context-aware penetration testing of web applications, APIs, endpoint agents, thick clients, identity systems, and cloud-native services. - Use Claude and Codex to analyze code paths, trace data flows, identify attack surfaces, and generate targeted test cases. - Threat Hunting Skills & Fuzz Factory Plugins: - Build AI-powered threat hunting skills and fuzz factory plugins using Claude and Codex. - Develop custom fuzzers that understand product-specific protocols, input formats, and business logic. - Create reusable skills and agent workflows that automate discovery of vulnerability classes. - Proof-of-Concept Exploit Development: - Develop working proof-of-concept exploits for discovered vulnerabilities. - Use Claude and Codex to accelerate exploit development, generate payloads, and validate exploitation chains. - Vulnerability Validation & Remediation Partnership: - Validate vulnerabilities from all sources and confirm exploitability. - Deliver specific fix recommendations to engineering teams. - Cyber Defense & Architect Partnership: - Partner with Cyber Defense and Security Architects to translate offensive findings into defensive capabilities. - Work with Security Architects to identify emerging attack techniques. - Security Tooling & Automation: - Build and maintain AI-driven security testing tooling integrated into CI/CD pipelines. - Develop custom SAST rules and automated validation workflows using Claude and Codex. - Threat Modeling & Secure Design: - Participate in threat modeling exercises alongside Product Security Architects. - Identify abuse cases and map exploitation paths. Qualifications - 5+ years in Product Security, or Penetration Testing with direct hands-on testing and exploit development. - Strong expertise in web application and API security. - Proficiency with penetration testing tools and methodologies. - Hands-on experience using LLM platforms (Claude, Codex, or similar). - Experience building custom security tooling. - Strong understanding of common vulnerability classes. - Experience collaborating with defensive security teams. - Understanding of cloud security fundamentals (preferably AWS) and CI/CD pipeline security. - Strong communication skills. Preferred - Experience building AI-native security workflows. - Background in securing endpoint technologies. - Experience with mobile application security testing. - Familiarity with container security and infrastructure-as-code scanning. - Experience working with bug bounty programs. - Professional certifications such as OSWE, OSCP, GWAPT, GPEN, or equivalent. - Contributions to security research or open-source security tooling. How We'll Measure Success - Consistent discovery of meaningful vulnerabilities with validated PoC exploits. - AI-powered threat hunting skills and fuzz factory plugins actively finding vulnerability classes. - Validated findings include specific, implementable fix recommendations. - Offensive findings translate into measurable defensive improvements. - Reusable skills, prompts, and plugins you build are adopted by the broader Product Security team. - Engineering and security leadership trust your severity assessments. About Us BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. Learn more at www.beyondtrust.com .
Senior Network Security Engineer
SectigoSectigo is the most innovative provider of certificate lifecycle management (CLM), delivering solutions that help the world’s largest brands simplify how digital trust is managed and scaled. Sectigo’s automated, cloud-native CLM platform issues and manages digital certificates across enterprise environments, enabling organizations to reduce complexity, accelerate time to value, and strengthen security across environments. Sectigo is one of the largest, longest-standing, and most reputable CAs with more than 700,000 customers, including 65% of the Fortune 500. Sectigo holds six combined active leadership seats in the CA/Browser Forum and ETSI and brings two decades of delivering unparalleled digital trust. How we show up with each other and our customers every day is just as important, and we win as #OneSectigo by living out our core values - Support, Excellence, Communication, Teamwork, Integrity, Growth and Openness. We are committed to investing in our diverse teams where everyone understands their role and how they support our strategic goals, we drive operational excellence through scale and efficiency, and we strive to delight our customers and become the market leader in our industry. If you aspire to join a driven team that holds each other accountable to meeting our lofty goals and you’d like to be part of our growth story in delivering a market leading user experience, we’d like to talk to you.
Role Description We are looking for a talented Senior Network Security Engineer to join our growing global team at Sectigo. The Senior Network Security Engineer is an experienced, hands-on security practitioner responsible for deploying, configuring, and operating enterprise and cloud-delivered security platforms. This role has a strong emphasis on network, SASE, and Zero Trust security, including Palo Alto Networks technologies such as Strata Cloud Manager, GlobalProtect, and Prisma Access Browser. The role is operational in nature and embedded within a 24x7 Security Operations Center (SOC) environment. The engineer will actively support continuous monitoring, incident response, and platform optimization across on-prem and cloud environments, ensuring reliable, scalable, and compliant security controls. - Lead the design, implementation, and maintenance of enterprise and cloud-based security infrastructure - Deploy, configure, optimize, and maintain security platforms with a focus on Palo Alto Networks technologies - Administer and support Strata Cloud Manager, GlobalProtect, and Prisma Access Browser for secure access and Zero Trust enforcement - Support SASE, CASB, MDR, and SIEM integrations across hybrid and cloud environments - Perform continuous security monitoring and deep-dive analysis of security alerts and events - Serve as a key member of the incident response team, participating in detection, response, containment, and recovery activities - Collaborate with infrastructure, networking, cloud, and application teams to embed security controls into designs and deployments - Identify, assess, and mitigate security vulnerabilities, misconfigurations, and emerging threats - Ensure security tooling and architectures align with industry standards and regulatory requirements - Automate repetitive security operations and monitoring tasks using scripting and tooling - Maintain accurate documentation for security configurations, architectures, procedures, and incident response - Participate in a rotating on-call schedule, including nights and weekends, to support 24x7 operations - Perform other job-related duties as required This is a 12-Month Contract and remote position based in India. This is an individual contributor role, reporting to our Senior Manager, Cybersecurity Operations. The targeted compensation package for this role is between 20 LPA to 30 LPA. Qualifications - Minimum of 5 years of hands-on experience deploying, configuring, and maintaining enterprise cybersecurity platforms - Hands-on experience with Palo Alto Networks products, including: - Strata Cloud Manager - GlobalProtect - Prisma Access Browser - Strong understanding of network security, secure remote access, Zero Trust, and SASE architectures - Demonstrated experience securing cloud environments (AWS, Azure, and/or GCP) - Experience operating in a 24x7 SOC environment, supporting monitoring and incident response - Proficiency integrating and troubleshooting security tools across complex hybrid environments - Strong knowledge of security best practices and frameworks such as NIST and ISO 27001 - Ability to work a rotating on-call schedule, including nights and weekends - Ability to thrive in a fast-paced, operationally focused environment Requirements - Palo Alto certifications such as PCNSA or PCNSE - Experience with Zero Trust and identity-aware security models - Strong scripting and automation skills (Python, PowerShell, or similar) - Experience with SIEM platforms, log analysis, and detection tuning - Familiarity with compliance, audit support, and security control validation - Strong communication and cross-team collaboration skills Benefits - Sectigo is an Equal Opportunity Employer. - Commitment to providing equal opportunities throughout your career. - Strong sense of belonging and support for a respectful, inclusive workplace. - Use of Artificial Intelligence (AI) tools during the recruitment process. - Global team with a commitment to engagement and diversity.
Security Product Services Engineer
Rimini StreetExtraordinary technology solutions powered by extraordinary people
• Installation, configuration and troubleshooting of security products using the repeatable project plans under the guidance of Security Solutions Architects. • Work with the client’s IT teams to integrate the solution with various SIEM solutions • Provide complete post-implementation monitoring and provide various weekly/monthly/quarterly reports for the client as defined in the signed SOW. • Document various client implementation configurations and keep the configuration documents up to date. • Assist the client’s Primary Support Engineer and the account managers with the data to be shared with the client for various business reviews. • Work with the Onboard Project Managers (OPMs) to provide the status of the projects during the initial implementation stages. • Manage the security products related support cases for proper and timely updates in accordance to the SLAs for various clients. • Manage the product issue log and work with the Senior Solutions architects to provide the needed assistance for troubleshooting of product specific issues. • Create and manage the status updates for project plans utilizing the templates for all security products related projects for general product onboarding, professional services and managed services maintaining Rimini Street´s high standard SLAs and quality. • Self-training to learn the new security products for efficient implementation and support.



