Assist with the delivery of Application Security services, including but not limited to Application Security Assessments for various application types (web, mobile, IoT, thick client), Threat Modeling, Source Code Reviews, Application Architecture Reviews, Secure Development Training, and Secure SDLC Implementation
Assist with authoring assessment deliverables that are tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies
Contribute to Application Security research projects
Contribute to marketing initiatives via activities such as research, speaking at industry conferences, authoring blog articles and whitepapers, webinars, and contributing to security tools
Utilize automation, orchestration, and scripting to reduce manual processes, improving overall efficiency while also enabling new capabilities to meet the rapidly changing needs of our clients
Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry.
Foster client relationships by providing support and information
Maintain a strong desire to learn, adapt, and improve along with a rapidly-growing company
Perform other duties as assigned
Requirements
Experience with testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, OpenSSL, etc.
Experience reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#.
Internal operational DevSecOps experience is preferred.
InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience, is strongly preferred.
Standard industry certifications are preferred.
Minimum of two (1) years of experience performing Application Security assessments or an understanding of Application Security assessments.
Minimum of one (1) year of experience in an enterprise-level consulting services role
Over four (4+) combined years of IT and information security experience are preferred.
Internal operational (non-consulting) experience is strongly preferred.
Tech Stack
IoT
Java
JavaScript
PHP
Python
SDLC
Benefits
Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
12 corporate holidays and a Flexible Time Off (FTO) program
Healthy mobile phone and home internet allowance
Eligibility for retirement plan after 2 months at open enrollment