Base Career helps you apply smarter for this job.
Key skills for this role
We are looking for a skilled Application Security Consultant to support the delivery of GuidePoint Security’s Application Security service offerings, including Application Security Assessments for web, mobile, and thick client applications, AI/LLM and Agentic Application Security Assessments, Threat Modeling, Source Code Reviews, Application Architecture Reviews, Secure Development Training, and Secure SDLC Implementation. This role will engage in the execution of challenging and complex technical assessments and the development of new and evolving service capabilities while providing “Wow Them” service to clients and/or internal customers or co-workers.
The Application Security Consultant will be required to demonstrate strong offensive application testing, secure code review, and AI/LLM security skills, lead by influence, and apply strong business and technical acumen to translate technical findings into realistic remediation strategies that align with client business objectives and priorities. As a technically adept and reliable team member, you will leverage your knowledge, skills, and experience to deliver exceptional results for the Practice’s core professional service offerings, share knowledge with team members, and help shape the Practice’s future.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Central, USA
Central, USA
, USA
Reston, USA
Chantilly, USA
North East, USA
Falls Church, USA
Central, USA
Central, USA
, USA
North East, USA
High School Diploma + 5 years of experience OR Bachelor’s Degree (BS/BA) + 2 years of experience OR Master’s Degree (MS/MA)
Minimum of two (2) years of experience performing Application Security assessments
Minimum of one (1) year of experience in an enterprise-level consulting services role
Experience with testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, OpenSSL, etc.
Experience reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#
Hands-on experience testing AI/LLM-powered applications and agentic AI systems (chatbots, RAG pipelines, autonomous/multi-agent workflows) for prompt injection, data leakage, excessive agency, insecure output handling, and tool/function-calling abuse
Familiarity with the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, and practical experience testing against them
General AI fluency and practical usage, including working with LLM APIs/SDKs (e.g., OpenAI, Anthropic, Bedrock, Azure OpenAI) and modern AI-assisted development workflows
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Over four (4+) combined years of IT and information security experience
Internal operational (non-consulting) experience is strongly preferred, particularly internal operational DevSecOps experience
Experience building AI agents, agent skills, custom tools, and full AI-assisted testing harnesses (e.g., MCP servers, LLM-orchestrated automation, agentic workflows) to support or scale security assessments
InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience, is strongly preferred
Standard industry certifications
Private cybersecurity services and solutions firm serving businesses and government agencies with consulting, engineering, and managed security.
Visit company websiteJobs and hiring trendsFull-time
Entry · 2+ years experience
Remote
Apply faster on company sites with our extension.