Application Security Consultant- Remote (Anywhere in the U.S.)

🏢 GuidePoint Security LLC · all 38 jobs
📍 United States
📅 Posted Sep 18, 2026 · via Himalayas
🏷 Application Security, Security Consulting, Penetration Testing, Offensive Security, Cybersecurity, Application Security Consultant +5 more
Apply on original site ↗

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description:

We are looking for a skilled Application Security Consultant to support the delivery of GuidePoint Security’s Application Security service offerings, including Application Security Assessments for web, mobile, and thick client applications, AI/LLM and Agentic Application Security Assessments, Threat Modeling, Source Code Reviews, Application Architecture Reviews, Secure Development Training, and Secure SDLC Implementation. This role will engage in the execution of challenging and complex technical assessments and the development of new and evolving service capabilities while providing “Wow Them” service to clients and/or internal customers or co-workers.

The Application Security Consultant will be required to demonstrate strong offensive application testing, secure code review, and AI/LLM security skills, lead by influence, and apply strong business and technical acumen to translate technical findings into realistic remediation strategies that align with client business objectives and priorities. As a technically adept and reliable team member, you will leverage your knowledge, skills, and experience to deliver exceptional results for the Practice’s core professional service offerings, share knowledge with team members, and help shape the Practice’s future.
About the Application Security Practice:

The Application Security Practice is responsible for helping clients identify, understand, and remediate risk in the applications they build and buy. We perform hands-on technical assessments, threat modeling, secure code reviews, and architecture reviews, and we build and mature application security programs and Secure SDLC capabilities across our clients’ organizations.

Our team of application security consultants, secure code reviewers, and AI/LLM security specialists focuses on modern web, mobile, IoT, and thick client platforms as well as AI-native and agentic architectures, testing against industry standards such as the OWASP Top 10, the OWASP Top 10 for LLM Applications, and the OWASP Top 10 for Agentic Applications. We partner with client development, DevSecOps, and security leadership teams to reduce application risk and embed security throughout the development lifecycle.

The Practice’s offerings evolve perpetually in response to emerging threats and diverse client needs. Key areas of focus include:

- Advancing AI/LLM and agentic application security testing methodologies as the threat landscape rapidly evolves

- Building AI-driven tooling, custom agents, and automation harnesses that improve testing coverage, consistency, and efficiency

- Publishing original security research and contributing to the broader InfoSec community through conference talks, blogs, whitepapers, and open-source tooling

Roles and Responsibilities:

- Deliver Application Security services, including but not limited to Application Security Assessments for various application types (web, mobile, AI, thick client), Threat Modeling, and Source Code Reviews.

- Perform AI/LLM and Agentic Application Security Assessments, including prompt injection testing, model/guardrail bypass, excessive agency abuse, tool-calling exploitation, RAG poisoning, and other attacks mapped to the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications

- Assess agentic AI architectures (e.g., LangChain, CrewAI, AutoGPT, MCP-based agents, Salesforce Agentforce) for excessive agency, insecure tool/function integrations, goal manipulation, cross-agent/cross-prompt injection, a

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you