Application Security Consultant

Direct Defense

Englewood (CO)

On-site

USD 100,000 - 108,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401(k)
AD&D Insurance
Dental Insurance
Disability insurance
Health insurance
Life insurance
Vision insurance
Flex PTO
Paid certification and CE

Job summary

DirectDefense is seeking an Application Security Consultant for a contract role to assess customer applications, identify vulnerabilities, and drive remediation with development teams. You will perform dynamic testing and static code reviews, using Burp Suite and other tools, while staying current with OWASP ASVS and industry best practices.

The role emphasizes collaboration, clear communication, and hands-on testing across security domains, with a schedule that supports a standard work week and

Qualifications

  • 1-3 years of hands-on experience in network/infrastructure security and penetration testing.
  • Bachelor's degree in CS, Engineering, Math, or related field.
  • Strong understanding of application security principles and common vulnerabilities.
  • Experience in performing dynamic and static code reviews.
  • Familiarity with Burp Suite vulnerability scanning tools.
  • Excellent written and verbal communication skills.
  • Experience in automated and manual application testing is a big plus.
  • Certifications such as OSCP, BSCP, OSWE, GWAPT or related offensive security certificates are a plus.
  • Knowledge of web application vulnerabilities and exploitation techniques.

Responsibilities

  • Conduct thorough analysis to identify and exploit vulnerabilities in customer applications.
  • Collaborate with development teams to creatively remediate identified vulnerabilities and enhance application security.
  • Perform dynamic testing and static code reviews to identify security vulnerabilities and weaknesses.
  • Utilize industry-leading tools, with a focus on application testing workspaces such as Burp Suite.
  • Stay abreast of the latest developments in application security, tools, and methodologies such as OWASP ASVS

Skills

Application security
Vulnerability assessment
Dynamic testing
Static code reviews
Burp Suite familiarity
Communication skills

Education

Bachelor's degree in CS/Engineering/Math or related

Tools

Burp Suite
OWASP ASVS

Job description

Are you passionate about application security and ready to make an immediate impact in a contract role? We are seeking a motivated Application Security Consultant with experience in software development, DevOps, or software quality assurance—or a strong foundation in application security. In this role, you will assess customer applications, identify and validate vulnerabilities, leverage innovative security tools, and recommend practical remediation strategies.

Responsibilities:

  • Conduct thorough analysis to identify and exploit vulnerabilities in customer applications.
  • Collaborate with development teams to creatively remediate identified vulnerabilities and enhance application security.
  • Perform dynamic testing and static code reviews to identify security vulnerabilities and weaknesses.
  • Utilize industry-leading tools, with a focus on application testing workspaces such as Burp Suite.
  • Stay abreast of the latest developments in application security, tools, and methodologies such as OWASP ASVS

Qualifications:

  • 1-3 years of hands-on experience in network/infrastructure security and penetration testing.
  • Bachelor's degree in Computer Science, Engineering, Math, or a related field (or equivalent hands-on experience, classroom project work, or internship).
  • Strong understanding of application security principles and common vulnerabilities.
  • Experience in performing dynamic and static code reviews.
  • Familiarity with vulnerability scanning tools, specifically Burp Suite.
  • Excellent written and verbal communication skills, with the ability to convey complex security topics clearly and concisely to diverse audiences.
  • Experience in automated and manual application testing is a big plus.

Preferred Skills:

  • Certifications such as OSCP, BSCP, OSWE, GWAPT or related offensive security certifications are a strong plus.
  • Knowledge of common web application vulnerabilities and exploitation techniques.
  • Understanding of cryptography, authentication, and authorization mechanisms.
  • Excellent problem-solving skills and a proactive approach to addressing security concerns.
  • Effective communication and collaboration skills to work with cross-functional teams.
  • Experience with automated and manual application testing is a significant plus.
  • AWS experience is a big plus.

Salary Range: 100K-108K + up to 10% annual bonus

Benefits include:

  • 401(k)
  • AD&D Insurance
  • Dental Insurance
  • Disability insurance
  • Health insurance
  • Life insurance
  • Vision insurance
  • Flex PTO program
  • Paid certification and continuing education

Work schedule: Monday through Friday

Work hours: 40 hours a week

A little about DirectDefense

Since coming together in 2011 to form DirectDefense, our team has been committed to offering Cybersecurity defense strategies that are unmatched in the industry. Whether we are performing assessments of networks, platforms, and applications or applying managed services to improve your organization’s security posture, we are focused on providing world-class services that don’t just work–they work for you.

OUR MISSION

We establish partnerships with our clients based on trust and results. We leverage our deep industry knowledge and expertise to identify and remediate blind spots in your security program, provide meaningful visibility of your entire enterprise, and align your organization with security best practices and compliance standards.

OUR VISION

We aim to secure organizations across all industries against advanced threats and attacks in today’s world. Partnering with organizations, we provide unmatched information security services designed to improve your overall security posture, close gaps, and continuously track vulnerabilities through ongoing education and support.

A little about DirectDefense

Since coming together in 2011 to form DirectDefense, our team has been committed to offering unmatched cybersecurity defense strategies. Whether we are performing assessments of networks, platforms, and applications or applying managed services to improve your organization’s security posture, we are focused on providing world-class services that don’t just work–they work for you.

OUR MISSION

We establish partnerships with our clients based on trust and results. We leverage our deep industry knowledge and expertise to identify and remediate blind spots in your security program, provide meaningful visibility of your entire enterprise, and align your organization with security best practices and compliance standards.

OUR VISION

We aim to secure organizations across all industries against advanced threats and attacks in today’s world. Acting in partnership with organizations, we will provide unmatched information security services designed to improve your overall security posture, close gaps, and track vulnerabilities on an ongoing basis through continued education and support.

PAY TRANSPARENCY

In accordance with applicable state laws, we are providing a good‑faith estimate of the compensation range for this role. The anticipated salary range for this position is $90,000 to $100,000 per year. Actual compensation will be based on several factors, including but not limited to the candidate’s qualifications, experience, skills, and location. This position may also be eligible for bonus incentives and a comprehensive benefits package.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

Direct Defense • Northern (KY)

Hybrid
USD 96,000 - 124,000
Senior Application Security Engineer
Senior Application Security Engineer

Agile Defense • Northern (KY)

Hybrid
USD 140,000 - 145,000
Health Insurance
Life Insurance
Paid Time Off
+3
Security Engineer
Security Engineer

Dahl Consulting • Minneapolis (MN)

Hybrid
USD 103,000 - 135,000
Offensive Security & Code Analysis Engineer
Offensive Security & Code Analysis Engineer

Districttechgroup • Washington

Hybrid
USD 80,000 - 120,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+1
Senior Application Security Engineer
Senior Application Security Engineer

Signature IT World Inc • New York (NY)

On-site
USD 100,000 - 150,000
Application Security Engineer - Plano, TX
Application Security Engineer - Plano, TX

Motion Recruitment Partners LLC • Plano (TX)

On-site
USD 120,000 - 180,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Application Security Engineer - Chandler, AZ
Application Security Engineer - Chandler, AZ

Motion Recruitment Partners LLC • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Senior Application Security Engineer
Senior Application Security Engineer

Agile Defense • United States

Remote
USD 110,000 - 165,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital • Reno (NV)

On-site
USD 111,000 - 145,000
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Application Offensive Security Consultant
Application Offensive Security Consultant

Pipe Recruit • Jersey City (NJ)

Hybrid
USD 83,000 - 165,000