> Markdown version of [/jobs/ext/2169691-application-security-consultant](https://www.wearedevelopers.com/jobs/ext/2169691-application-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Consultant - **Company:** Directdefense, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $145,600.0 - $187,200.0 - **Contract:** Internship / Graduate position - **Skills:** Amazon Web Services, Software System Penetration Testing, Application Testing, User Authentication, Burp Suite, Code Review, Cyber Security, DevOps, Open Web Application Security, Software Engineering, Software Quality Assurance (SQA), Web Applications, Software Security, GWAPT, Information Technology, Vulnerability Analysis - **Published:** August 21, 2026 - **Apply:** https://www.workingnomads.com/job/go/1806020/ ## About the Role Are you passionate about application security and ready to make an immediate impact in a contract role? We are seeking a motivated Application Security Consultant with experience in software development, DevOps, or software quality assurance-or a strong foundation in application security. In this role, you will assess customer applications, identify and validate vulnerabilities, leverage innovative security tools, and recommend practical remediation strategies., * 1-3 years of hands-on experience in network/infrastructure security and penetration testing. * Bachelor's degree in Computer Science, Engineering, Math, or a related field (or equivalent hands-on experience, classroom project work, or internship). * Strong understanding of application security principles and common vulnerabilities. * Experience in performing dynamic and static code reviews. * Familiarity with vulnerability scanning tools, specifically Burp Suite. * Excellent written and verbal communication skills, with the ability to convey complex security topics clearly and concisely to diverse audiences. * Experience in automated and manual application testing is a big plus. * Preferred Skills: * Certifications such as OSCP, BSCP, OSWE, GWAPT or related offensive security certifications are a strong plus. * Knowledge of common web application vulnerabilities and exploitation techniques. * Understanding of cryptography, authentication, and authorization mechanisms. * Excellent problem-solving skills and a proactive approach to addressing security concerns. * Effective communication and collaboration skills to work with cross-functional teams. * Experience with automated and manual application testing is a significant plus. * AWS experience is a big plus. ## Description * Conduct thorough analysis to identify and exploit vulnerabilities in customer applications. * Collaborate with development teams to creatively remediate identified vulnerabilities and enhance application security. * Perform dynamic testing and static code reviews to identify security vulnerabilities and weaknesses. * Utilize industry-leading tools, with a focus on application testing workspaces such as Burp Suite. * Stay abreast of the latest developments in application security, tools, and methodologies such as OWASP ASVS, We aim to secure organizations across all industries against advanced threats and attacks in today's world. Partnering with organizations, we provide unmatched information security services designed to improve your overall security posture, close gaps, and continuously track vulnerabilities through ongoing education and support. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)