
Application Security Consultant- Remote (Anywhere in the U.S.)/ 4 days ago
Quick Summary
GuidePoint Security delivers trusted cybersecurity expertise, solutions, and services, empowering organizations to make informed decisions and minimize risk. Through a comprehensive, three-tiered approach to security posture and ecosystem evaluation, GuidePoint assists leading organizations, including Fortune 500 companies and U.S. government agencies, in identifying threats, optimizing resources, and integrating effective solutions for risk mitigation.
General Description
GuidePoint Security seeks a skilled Application Security Consultant to deliver our comprehensive Application Security services. This includes Application Security Assessments for web, mobile, and thick client applications, AI/LLM and Agentic Application Security Assessments, Threat Modeling, Source Code Reviews, Application Architecture Reviews, Secure Development Training, and Secure SDLC Implementation. The role involves executing complex technical assessments and developing new service capabilities, ensuring exceptional client and internal customer service.
The ideal Application Security Consultant will possess strong skills in offensive application testing, secure code review, and AI/LLM security. This role requires leadership by influence and the ability to translate technical findings into practical remediation strategies aligned with client business objectives. As a key team member, you will deliver outstanding results for professional service offerings, share expertise, and contribute to the Practice's future growth.
About the Application Security Practice
Our Application Security Practice assists clients in identifying, understanding, and remediating application risks. We conduct hands-on technical assessments, threat modeling, secure code reviews, and architecture reviews. We also develop and mature application security programs and Secure SDLC capabilities for client organizations.
Our team of application security consultants, secure code reviewers, and AI/LLM security specialists focuses on modern web, mobile, IoT, and thick client platforms, alongside AI-native and agentic architectures. We perform testing against industry benchmarks like the OWASP Top 10, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic Applications. We collaborate with client development, DevSecOps, and security leadership to reduce application risk and integrate security throughout the development lifecycle.
Our Practice's offerings continuously evolve to address emerging threats and diverse client requirements. Key focus areas include:
- Advancing AI/LLM and agentic application security testing methodologies in a rapidly evolving threat landscape.
- Developing AI-driven tooling, custom agents, and automation harnesses to enhance testing coverage, consistency, and efficiency.
- Publishing original security research and contributing to the InfoSec community via conference talks, blogs, whitepapers, and open-source tools.
Roles and Responsibilities
- Deliver Application Security services, including Application Security Assessments for web, mobile, AI, and thick client applications, Threat Modeling, and Source Code Reviews.
- Conduct AI/LLM and Agentic Application Security Assessments, covering prompt injection testing, model/guardrail bypass, excessive agency abuse, tool-calling exploitation, and RAG poisoning, aligned with the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications.
- Evaluate agentic AI architectures (e.g., LangChain, CrewAI, AutoGPT, MCP-based agents, Salesforce Agentforce) for excessive agency, insecure tool/function integrations, goal manipulation, cross-agent/cross-prompt injection, and unsafe autonomy boundaries.
- Author detailed assessment deliverables for technical and managerial audiences, outlining technical execution, deficiencies, business impact, and realistic remediation strategies.
- Develop and enhance AI-driven tooling for assessments, including custom agents, agent skills, tool integrations, and automation harnesses leveraging LLMs to improve testing coverage and efficiency. Apply hands-on AI/LLM knowledge (prompt engineering, model behavior, RAG) to test AI systems and build internal AI-assisted capabilities.
- Employ automation, orchestration, scripting, and AI-assisted tooling to streamline processes and enhance efficiency, meeting evolving client needs.
- Contribute to Application Security research projects, including emerging AI and agentic threat research. Support marketing through conference speaking, blog/whitepaper authorship, webinars, and security tool contributions.
- Cultivate client relationships and continuously enhance skills in the information security industry, particularly in the rapidly evolving AI/LLM and agentic security landscape.
- Demonstrate a strong commitment to learning, adaptation, and improvement within a growing company, and perform assigned duties.
Required Experience and Education
- High School Diploma + 5 years of experience OR Bachelor's Degree (BS/BA) + 2 years of experience OR Master's Degree (MS/MA).
- Minimum two (2) years of experience conducting Application Security assessments.
- Minimum one (1) year of experience in an enterprise-level consulting services role.
- Proficiency with security testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, and OpenSSL.
- Experience with source code review in JavaScript, Python, Java, C++, PHP, or C#.
- Hands-on experience testing AI/LLM-powered applications and agentic AI systems (chatbots, RAG pipelines, multi-agent workflows) for prompt injection, data leakage, excessive agency, insecure output handling, and tool/function-calling abuse.
- Familiarity with the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications, with practical testing experience.
- General AI fluency and practical usage, including working with LLM APIs/SDKs (e.g., OpenAI, Anthropic, Bedrock, Azure OpenAI) and modern AI-assisted development workflows.
- A proactive approach to leveraging emerging technologies, including AI tools, for problem-solving and business outcomes.
Preferred Experience and Education
- Over four (4+) combined years of IT and information security experience.
- Strong preference for internal operational (non-consulting) experience, especially DevSecOps experience.
- Experience developing AI agents, agent skills, custom tools, and AI-assisted testing harnesses (e.g., MCP servers, LLM-orchestrated automation, agentic workflows) to scale security assessments.
- Significant InfoSec community involvement, including conference speaking, blog/whitepaper authorship, or podcast production.
- Relevant industry certifications.
Travel Requirements
Up to 20% travel may be required.
Physical Requirements
- Sedentary work.
- Substantial movement of wrists, hands, and/or fingers for a minimum of 8 hours daily.
- Close visual acuity required for computer terminal viewing and/or extensive reading for a minimum of 8 hours daily.
GuidePoint Security utilizes Greenhouse Software for applicant tracking and Zoom Scheduler for HR screen requests. Please monitor your SPAM folder to ensure receipt of application updates, as emails may occasionally be blocked.
Why GuidePoint?
GuidePoint Security is a rapidly expanding, profitable, privately-held value-added reseller specializing exclusively in Information Security. Since 2011, GuidePoint has grown to over 1,300 employees, forged strategic partnerships with top security vendors, and become a trusted advisor to over 6,200 customers.
Our core values drive business success and foster an enjoyable workplace. At GuidePoint, you'll collaborate with knowledgeable, skilled, and experienced colleagues who offer mentorship and guidance.
This presents a unique opportunity to advance your career within one of the nation's fastest-growing companies.
Some Added Perks
- Primarily remote workforce (U.S. based only; some travel or on-site work for Federal positions may be required).
- Group Medical Insurance options:
- Zero Deductible PPO Plan (GuidePoint covers 90% of employee premium, 70% for family plans).
- High Deductible Health Plan with HSA (GuidePoint covers 100% of employee premium, 75% for family plans). GPS contributes $850 annually per employee / $1750 annually per family to HSA in quarterly installments.
- Group Dental Insurance: GuidePoint covers 100% of employee premium, 75% for family plans.
- 12 corporate holidays and a Flexible Time Off (FTO) program.
- Generous mobile phone and home internet allowance.
- Retirement plan eligibility after 2 months at open enrollment.
- Pet Benefit Option.

