> Markdown version of [/jobs/ext/2529241-senior-application-security-consultant](https://www.wearedevelopers.com/jobs/ext/2529241-senior-application-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Consultant - **Company:** Kalles Group - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $110,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Applications Architecture, Microsoft Azure, Cyber Security, Continuous Integration, Information Systems Security Architecture Professional, Software Engineering, Software Vulnerability Management, Google Cloud, Spring Cloud, Large Language Models, Software Security, Software Application Programming, Information Technology, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=02fc4e78e81124ec ## About the Role * 8+ years of experience in cybersecurity with significant hands-on experience performing application security assessments * Strong understanding of secure software development practices, secure design principles, and vulnerability management * Experience performing threat modeling and secure architecture reviews * Hands-on experience with application security testing technologies including SAST, DAST, SCA, and related security platforms * Experience assessing cloud-native applications running in AWS, Azure, or Google Cloud Platform * Knowledge of APIs, modern application architectures, and secure software development methodologies * Experience developing security standards, assessment methodologies, or security review processes * Strong written and verbal communication skills with the ability to influence engineering and product teams * Ability to prioritize security risk and communicate remediation strategies to both technical and business stakeholders * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent professional experience, * Professional certifications such as CISSP, OSCP, CSSLP, CCSP, CISA, or similar * Experience applying AI or large language model (LLM) technologies to application security workflows * Experience building security automation or AI-assisted assessment capabilities * Experience working within a formal Design Review or Security Architecture review process * Experience with DevSecOps practices, CI/CD security integration, or developer security enablement * Experience mentoring engineers and promoting secure-by-design principles across development organizations ## Description As a Senior Application Security Consultant, you will help our client strengthen application security by leading comprehensive security assessments across internally developed and third-party applications. Working closely with software engineers, architects, product teams, and security professionals, you will identify security risks early in the development lifecycle and help teams build secure solutions by design. This role blends technical expertise with collaboration and innovation. You will establish and evolve security assessment methodologies, leverage automation and AI-enabled capabilities to improve assessment efficiency, and provide actionable guidance that enables engineering teams to reduce risk while maintaining development velocity. You will also contribute to secure design standards, threat modeling activities, and continuous improvement initiatives that elevate application security across the organization., * Perform comprehensive security assessments for internally developed and third-party applications * Partner with engineering, product, and architecture teams to identify security risks during application design and development * Conduct secure design reviews and provide security approval recommendations for new and existing solutions * Develop and enhance standardized security assessment methodologies, frameworks, and best practices * Utilize AI-enabled tools and automation to improve assessment efficiency, threat modeling, compliance validation, and software supply chain analysis * Document assessment findings and deliver practical, risk-based remediation recommendations * Validate remediation efforts and verify that identified security issues have been successfully addressed * Develop reusable secure design patterns and security guidance for engineering teams * Monitor emerging threats, vulnerabilities, and evolving application security practices * Collaborate with cross-functional stakeholders to embed security throughout the software development lifecycle * Contribute to continuous improvement initiatives within the organization's application security program, + Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly. + Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth. + Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Serverless Architectures with Spring Cloud Functions and Knative](https://www.wearedevelopers.com/videos/814-serverless-architectures-with-spring-cloud-functions-and-knative) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)