Application Security Consultant

🔥 0 minutes ago

⛰️ Colorado – Remote

infoinfo

💵 $90k - $100k / year

⏰ Full Time

🟢 Junior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of DirectDefense

DirectDefense

51 - 200 employees

Founded 2012

🔒 Cybersecurity

🏢 Enterprise

🏛️ Government

Cybersecurity • Enterprise • Government

DirectDefense is a cybersecurity services company providing managed detection and response (MDR) and managed security services (MSSP), threat mitigation, security testing, compliance support, OT/ICS security, IoT/IIoT and smart device testing, architecture reviews, incident response/forensics (Peace of Mind / E-Discovery), AI readiness, application, network and cloud security, and a ThreatAdvisor platform for visibility. They serve enterprise and public sector customers across verticals including aerospace, automotive, energy/utilities, financial services, healthcare, retail, technology and government. The company offers professional services (strategy & planning, talent acquisition), research & validation, and compliance services (PCI, CMMC, HIPAA, ISO 27001, GDPR, NERC CIP, FISMA/FedRAMP). DirectDefense emphasizes OT/ICS protection, connected systems, and rapid OT cybersecurity assessments. They market MDR+MSSP offerings, incident response, and security assessments, and have partnerships/government contracts.

📋 Description

• Conduct thorough analysis to identify and exploit vulnerabilities in customer applications • Collaborate with development teams to remediate identified vulnerabilities and enhance application security • Perform dynamic testing and static code reviews to identify security vulnerabilities and weaknesses • Utilize industry-leading tools, focusing on application testing workspaces such as Burp Suite • Stay current with developments in application security, tools, and methodologies such as OWASP ASVS • Assess customer applications, validate vulnerabilities, and recommend practical remediation strategies

🎯 Requirements

• 1-3 years of hands-on experience in network/infrastructure security and penetration testing • Bachelor’s degree in Computer Science, Engineering, Math, or a related field, or equivalent hands-on experience, classroom project work, or internship • Strong understanding of application security principles and common vulnerabilities • Experience in performing dynamic and static code reviews • Familiarity with vulnerability scanning tools, specifically Burp Suite • Excellent written and verbal communication skills, with the ability to convey complex security topics clearly and concisely to diverse audiences • Certifications such as OSCP, BSCP, OSWE, GWAPT, or related offensive security certifications are a strong plus • Knowledge of common web application vulnerabilities and exploitation techniques • Understanding of cryptography, authentication, and authorization mechanisms • Experience with automated and manual application testing is a plus • AWS experience is a plus

🏖️ Benefits

• 401(k) • AD&D Insurance • Dental Insurance • Disability insurance • Health insurance • Life insurance • Vision insurance • Flex PTO program • Paid certification and continuing education • Up to 10% annual bonus (listed in the compensation section)

Apply Now

Similar Jobs

🔥 12 hours ago

LaunchDarkly

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Product Security Engineer securing LaunchDarkly’s feature-management platform through threat modeling and cloud security. Automating security workflows and applying AI to reduce risk and toil.

🕒 Yesterday

Dragonfli Group

11 - 50

🔒 Cybersecurity

💼 Consulting

Junior Security Engineer supporting Dragonfli Group’s federal cybersecurity modernization program. Configuring cloud security, automation, hardening, monitoring, and compliance tooling.

🕒 2 days ago

COFENSE

201 - 500

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Information security program manager managing Cofense customer portfolios and simulated phishing defense programs. Delivering security guidance, remediation reporting, and product adoption support across the United States.

🕒 2 days ago

Imagineeer

11 - 50

🏛️ Government

🔒 Cybersecurity

💼 Consulting

Security Control Assessor applying NIST frameworks to evaluate federal HHS-ACF system security. Documenting evidence, testing controls, supporting vulnerability analysis, and developing compliance deliverables.

🕒 2 days ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Security Advisor guiding CrowdStrike Falcon Complete customers toward stronger security postures. Assessing Falcon environments, recommending remediation, and resolving technical issues for government-cloud customers.