> Markdown version of [/jobs/ext/550172-senior-security-consultant](https://www.wearedevelopers.com/jobs/ext/550172-senior-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Consultant - **Company:** Directdefense, Inc. - **Location:** Englewood, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Automation of Tests, Cyber Security, Information Systems Security Architecture Professional, Red Team (Cyber Security), Cyber Threat Analysis, Information Technology, Vulnerability Analysis - **Published:** June 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b856e31358793256 ## About the Role Do you have experience in Vuls?, The Senior Security Consultant at DirectDefense will be a crucial member of our cybersecurity team. They are responsible for identifying security vulnerabilities within our clients' environments and providing technical remediation guidance. This role involves conducting comprehensive penetration tests, performing detailed vulnerability assessments, and leading Red Team engagements to simulate sophisticated attacks. The ideal candidate will possess extensive technical expertise, a deep understanding of both offensive and defensive IT concepts, and the ability to communicate complex security issues effectively. With a focus on staying current with the latest vulnerabilities and technology trends, the Senior Security Consultant will develop and execute proof-of-concept exploits, create detailed reports, and recommend improvements to enhance clients' security postures. This position also involves mentoring junior testers and contributing to the development of innovative testing tools and, * 5-10 years of hands-on experience in network/infrastructure security and penetration testing. * Extensive knowledge of offensive toolkits and techniques used in network/infrastructure penetration testing. * Strong grasp of both offensive and defensive IT concepts, including common attack vectors and defense mechanisms. * Proven ability to stay current with the latest vulnerabilities, technology trends, and threat landscapes. * Exceptional ability to develop proof-of-concept exploits that accurately demonstrate identified vulnerabilities. * Excellent written and verbal communication skills, capable of conveying complex security topics in a clear, concise, and understandable manner to diverse audiences. * Professional certifications such as OSCP and OSEP are highly preferred. * Ability to travel up to 25% ## Description * Conduct comprehensive penetration tests to identify security vulnerabilities, assess their impact, and develop actionable remediation strategies. * Perform detailed vulnerability assessments and analyses of client networks, systems, servers, and other infrastructure components. * Lead Red Team exercises to simulate advanced persistent threats and measure an organization's readiness to detect, respond, and mitigate attacks. * Stay up to date with the latest vulnerabilities, technology trends, threat landscapes, and offensive toolkits used in penetration testing. Apply this knowledge to enhance testing methodologies. * Develop and execute proof-of-concept exploits to demonstrate the impact and severity of identified vulnerabilities. * Create comprehensive, accurate, and detailed reports and presentations for both technical and executive audiences, clearly communicating findings, risks, and remediation recommendations. * Design and develop scripts, tools, and methodologies to improve testing processes and efficiencies. * Mentor and guide less experienced penetration testers, fostering a culture of continuous learning and professional development. * Assist in scoping prospective engagements, managing client expectations, and lead engagements from kickoff through remediation. * Evaluate and recommend improvements to clients' security architectures, ensuring robust and resilient defenses., We aim to secure organizations across all industries against advanced threats and attacks in today's world. Acting in partnership with organizations, we will provide unmatched information security services designed to improve your overall security posture, close gaps, and track vulnerabilities on an ongoing basis through continued education and support. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How to add test automation to your project: The good, the bad, and the ugly](https://www.wearedevelopers.com/videos/1668-how-to-add-test-automation-to-your-project-the-good-the-bad-and-the-ugly) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)