DirectDefense Logo

DirectDefense

Application Security Consultant

Posted 22 Days Ago
Remote
Hiring Remotely in USA
70-90 Hourly
Junior
Remote
Hiring Remotely in USA
70-90 Hourly
Junior
Conduct application security assessments, identify and validate vulnerabilities, perform dynamic testing and static code reviews, and recommend remediation strategies. Collaborate with development teams to improve application security, use tools such as Burp Suite, and stay current with application security methodologies, web vulnerabilities, and exploitation techniques.
The summary above was generated by AI

Are you passionate about application security and ready to make an immediate impact in a contract role? We are seeking a motivated Application Security Consultant with experience in software development, DevOps, or software quality assurance—or a strong foundation in application security. In this role, you will assess customer applications, identify and validate vulnerabilities, leverage innovative security tools, and recommend practical remediation strategies.

Contract Length: Three months, with the possibility of an extension or conversion to a full-time position

Hourly Rate (1099): $70–$90 per hour

Responsibilities:

  • Conduct thorough analysis to identify and exploit vulnerabilities in customer applications.
  • Collaborate with development teams to creatively remediate identified vulnerabilities and enhance application security.
  • Perform dynamic testing and static code reviews to identify security vulnerabilities and weaknesses.
  • Utilize industry-leading tools, with a focus on application testing workspaces such as Burp Suite.
  • Stay abreast of the latest developments in application security, tools, and methodologies such as OWASP ASVS

Qualifications:

  • 1-3 years of hands-on experience in network/infrastructure security and penetration testing.
  • Bachelor’s degree in Computer Science, Engineering, Math, or a related field (or equivalent hands-on experience, classroom project work, or internship).
  • Strong understanding of application security principles and common vulnerabilities.
  • Experience in performing dynamic and static code reviews.
  • Familiarity with vulnerability scanning tools, specifically Burp Suite.
  • Excellent written and verbal communication skills, with the ability to convey complex security topics clearly and concisely to diverse audiences.
  • Experience in automated and manual application testing is a big plus.

Preferred Skills:

  • Certifications such as OSCP, BSCP, OSWE, GWAPT or related offensive security certifications are a strong plus.
  • Knowledge of common web application vulnerabilities and exploitation techniques.
  • Understanding of cryptography, authentication, and authorization mechanisms.
  • Excellent problem-solving skills and a proactive approach to addressing security concerns.
  • Effective communication and collaboration skills to work with cross-functional teams.
  • Experience with automated and manual application testing is a significant plus.
  • AWS experience is a big plus.

Candidates must currently reside in the United States and be able to complete the client’s required U.S.-based background-screening process. Applicants must also be legally authorized to work in the United States without current or future sponsorship.

A little about DirectDefense

Since coming together in 2011 to form DirectDefense, our team has been committed to offering Cybersecurity defense strategies that are unmatched in the industry. Whether we are performing assessments of networks, platforms, and applications or applying managed services to improve your organization’s security posture, we are focused on providing world-class services that don’t just work–they work for you.

OUR MISSION

We establish partnerships with our clients based on trust and results. We leverage our deep industry knowledge and expertise to identify and remediate blind spots in your security program, provide meaningful visibility of your entire enterprise, and align your organization with security best practices and compliance standards.

OUR VISION

We aim to secure organizations across all industries against advanced threats and attacks in today’s world. Partnering with organizations, we provide unmatched information security services designed to improve your overall security posture, close gaps, and continuously track vulnerabilities through ongoing education and support.

Similar Jobs

20 Days Ago
Remote or Hybrid
USA
115K-160K Annually
Senior level
115K-160K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Deliver generative AI-enabled source code review and application security engagements. Coordinate with leadership, organize resources, refine and present assessment findings, document recommendations, and mentor junior red team members. Support penetration testing projects, including external and web application testing, while managing engagement delivery and improving security assessment technologies and workflows.
Top Skills: AutomationBurp SuiteGenerative AiNessusScriptingSource Code Review
23 Days Ago
In-Office or Remote
Burlington, MA, USA
124K-185K Annually
Senior level
124K-185K Annually
Senior level
On-Demand • Security • Software
Leads client engagements focused on application security and DevSecOps transformation. Configures application security testing tools in CI/CD pipelines, supports vulnerability triage, conducts maturity assessments using BSIMM and NIST SSDF, and develops multi-year strategic roadmaps. Facilitates executive workshops, presents recommendations to security and engineering leaders, creates maturity models and dashboards, and contributes to thought leadership on secure software governance.
Top Skills: Ai/Ml AssuranceAWSBsimmCi/CdDastDevsecopsGitlab Ci/CdGrafanaNist SsdfOwasp SammPythonSastScaSdlcSscrm
11 Minutes Ago
In-Office or Remote
South Carolina, USA
43K-78K Annually
Junior
43K-78K Annually
Junior
Other • Utilities
Acquire new small and medium-sized business accounts through prospecting, cold calling, networking, lead generation, and referrals. Recommend tailored wireless products and services, negotiate and close deals, manage sales funnels, report forecasts, and meet monthly sales quotas. Participate in product training and sales meetings while developing prospecting, call execution, and relationship-management skills.
Top Skills: Sales Force Automation

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account