1

Application Security Consultant Jobs (NOW HIRING)

Be Seen First

"All candidates must be directly contracted by ASK Consulting on their payroll and cannot be subcontracted. We are unable to provide sponsorship at this moment". Job Title: Application Security ...

Stefanini is looking for an SAP Security Consultant(Dearborn, MI) For quick apply, please reach out ... Work closely with Application security team members and support all security work Provide ...

Possessing a deep understanding of AWS products and services, as a Cloud Security Consultant you ... If you have a disability and need a workplace accommodation or adjustment during the application ...

AWS Security Consultant Location : Boston, MA Job Type : Permanent Full Time * Comprehensive ... In-depth knowledge of firewalls, (host based, network and web application firewalls), IDS and IPS ...

Description Security Consultant Location: Chicago or Remote US About VikingCloud VikingCloud is the ... web application architecture and security. * Providing clear, organized findings and ...

AssetMark is a leading strategic provider of innovative investment and consulting solutions serving ... The Application / SaaS Security Engineer is responsible for strengthening the security of ...

Application Security

Exton, PA · On-site

$56.75 - $75.75/hr

At least 5 years of experience in Business Process Consulting, problem definition, Architecture ... Conduct Security Code Review, Vulnerability Assessment and Consult Product Development Team to ...

AppSec Security Engineer

New York, NY

$64.25 - $86/hr

You will serve as a trusted security consultant and a hands-on engineer. You will review complex ... Own and evolve our application security program including establishing and maintaining SAST/DAST ...

Showing results 41-60

Application Security Consultant information

See salary details

$24

$56

$78

How much do application security consultant jobs pay per hour?

As of Jul 27, 2026, the average hourly pay for application security consultant in the United States is $56.36, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $64.42 per hour, depending on experience, location, and employer.

What are some common challenges faced by Application Security Consultants when working with development teams?

Application Security Consultants often encounter challenges such as bridging the gap between security best practices and fast-paced development cycles. They must effectively communicate complex security concepts to developers who may not have specialized security training, ensuring that security is integrated early without hindering productivity. Additionally, consultants need to prioritize vulnerabilities based on risk and help teams implement practical remediation strategies within project timelines. Building strong partnerships and fostering a culture of security awareness are key to overcoming these challenges.

What does an Application Security Consultant do?

An Application Security Consultant is responsible for identifying and mitigating security risks in software applications. They conduct security assessments, perform code reviews, and advise development teams on best practices for securing applications against threats such as data breaches and cyberattacks. Their work helps organizations protect sensitive information and comply with industry regulations. Additionally, they may assist in developing secure coding guidelines and provide training to developers.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically considered an entry to mid-level position, often suitable for candidates with some cybersecurity knowledge, basic understanding of security tools, and relevant certifications like CompTIA Security+ or Cisco CCNA Security. Advancement usually requires experience in incident response, threat analysis, and familiarity with security information and event management (SIEM) systems.

What is application security consultant job description?

An application security consultant evaluates and improves the security of software applications by identifying vulnerabilities, conducting security assessments, and recommending best practices. They often use tools like static and dynamic analysis software and may hold certifications such as Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP). The role requires strong knowledge of cybersecurity principles, programming skills, and the ability to communicate security risks effectively.

What is the difference between Application Security Consultant vs Security Analyst?

AspectApplication Security ConsultantSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentConsulting firms, tech companies, project-basedIn-house security teams, IT departments
Primary FocusIdentifying and mitigating application vulnerabilitiesMonitoring, analyzing security threats and incidents
Industry UsageSoftware development, cybersecurity consultingFinancial, healthcare, enterprise sectors

Application Security Consultants focus on securing software applications by identifying vulnerabilities and advising on best practices. Security Analysts monitor and analyze security threats within an organization. While both roles require cybersecurity certifications and involve protecting digital assets, their daily tasks and environments differ significantly.

What are the key skills and qualifications needed to thrive as an Application Security Consultant, and why are they important?

To thrive as an Application Security Consultant, you need a deep understanding of secure software development, vulnerability assessment, and knowledge of security frameworks, often supported by a degree in computer science and certifications like CISSP or CEH. Familiarity with tools such as Burp Suite, OWASP ZAP, static and dynamic analysis tools, and experience with secure coding practices are crucial. Strong analytical thinking, problem-solving abilities, and effective communication help consultants clearly convey risks and remediation strategies to both technical and non-technical stakeholders. These skills ensure robust application security, compliance with industry standards, and effective protection against evolving cyber threats.

Can you make $500,000 a year in cyber security?

Application Security Consultants with extensive experience, advanced certifications, and specialized skills can potentially earn $500,000 or more annually, especially in senior or leadership roles at large organizations or consulting firms. Achieving this level often requires a combination of technical expertise, industry reputation, and strategic responsibilities. Most cybersecurity professionals earn less, but top-tier consultants and those in high-demand markets can reach or exceed this income level.

How much does a security consultant get paid?

Application Security Consultants typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior or specialized consultants with certifications like CISSP or OSCP can earn higher salaries, especially in larger organizations or tech hubs.
More about Application Security Consultant jobs
What cities are hiring for Application Security Consultant jobs? Cities with the most Application Security Consultant job openings:
Who are the top companies hiring for Application Security Consultant jobs? The top employers for Application Security Consultant jobs are:
What states have the most Application Security Consultant jobs? States with the most job openings for Application Security Consultant jobs include:
What job categories do people searching Application Security Consultant jobs look for? The top searched job categories for Application Security Consultant jobs are:
Infographic showing various Application Security Consultant job openings in the United States as of July 2026, with employment types broken down into 77% Full Time, 17% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $117,232 per year, or $56.4 per hour.

Application Security Engineer

Bright Vision Technologies

Secaucus, NJ • Remote

$100K - $150K/yr

Full-time

Posted 4 days ago


Job description

Application Security Engineer – Remote
Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential.
Job Title: Application Security Engineer
Location: 100% Remote (U.S.)
Position Type: Full-time, Direct W2
Salary Range: $100,000–$150,000 Annually
Experience Required: 6+ years
Sponsorship: U.S. Citizens, Green Card Holders, EAD Holders, and H-1B transfer candidates are encouraged to apply. We are unable to sponsor new H-1B visa petitions for this position.
Job Summary:
We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production.
Key Responsibilities
  • Conduct threat modeling and security architecture reviews for new and existing applications and services.
  • Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components.
  • Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines.
  • Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking.
  • Build paved-road libraries and frameworks that make secure patterns the default for engineering teams.
  • Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses.
  • Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms.
  • Design and enforce secure authentication, authorization, session management, and cryptographic patterns.
  • Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments.
  • Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff.
  • Respond to security incidents involving application vulnerabilities or active exploitation.
  • Track and apply emerging threats and CVEs that may affect the application portfolio.
  • Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.
  • Stay current with application security research and emerging defensive tooling.
Required Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • Five or more years of application security or security engineering experience.
  • Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns.
  • Hands-on experience performing code review across at least two major languages.
  • Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling.
  • Strong understanding of authentication, authorization, and cryptographic primitives.
  • Experience with cloud security and modern infrastructure controls.
  • Strong communication skills with technical and non-technical audiences.
  • Proficiency in at least one programming language for tooling and automation.
  • Experience working closely with engineering teams in an Agile environment.
Preferred Qualifications
  • Industry certifications such as OSCP, OSCE, GWAPT, or CISSP.
  • Experience with offensive security tooling and red-team operations.
  • Bug bounty experience, public CVEs, or open-source security contributions.
  • Familiarity with AI/LLM application security considerations.
  • Exposure to regulated industries with strict compliance requirements.
How to Apply
Would you like to know more about this opportunity? For immediate consideration, please send your resume to venkat.r@bvteck.com or contact us at (908) 505-3899. Learn more about Bright Vision Technologies at www.bvteck.com.
Bright Vision Technologies is an Equal Opportunity Employer.
 

Equal Employment Opportunity (EEO) Statement

Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall.

BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees\' ability to perform their job duties may result in disciplinary action up to and including termination of employment.