1

Application Security Consultant Jobs (NOW HIRING)

Cybersecurity Consultant Iv, Application Security (greensboro, Nc) Full-time About the Job The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for ...

NY · On-site

... consulting & assessment services for products (software, services, devices, and large-scale ... As part of this role, you will use your technical background - in the Application Security domain ...

Business Security Consultant - South Bank, QLD Apply now Refer a friend Job no: 531867NM Brand ... Provide security architecture guidance on application design, API security, integration patterns ...

Description "All candidates must be directly contracted by ASK Consulting on their payroll and ... Application Security Engineer Location: Seattle, WA(Remote) Duration: 6 Months Pay rate: $67/Hr on ...

We provide a comprehensive range of software security services including consulting, training in both instructor-led and eLearning, mobile application security, and cloud services aimed at addressing ...

Manager, Application Security, DevSecOps

Albany, NY · On-site

$58.25 - $78/hr

KPMG is currently seeking a Manager, Application Security, DevSecOps to join our Enterprise ... Provide security consulting and subject-matter expertise to development and platform teams on ...

Application Security

Exton, PA · On-site

$56.75 - $75.75/hr

They are seeking an Application Security professional to conduct security code reviews ... Responsibilities : • At least 5 years of experience in Business Process Consulting, problem ...

About the Role The Application Security Senior Consultant will deliver generative AI enabled source code review based application security engagements. The Sr. Consultant is expected to be able to ...

Showing results 41-60

Application Security Consultant information

See salary details

$24

$56

$78

How much do application security consultant jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for application security consultant in the United States is $56.36, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $64.42 per hour, depending on experience, location, and employer.

What does an application security consultant do?

An Application Security Consultant is responsible for identifying and mitigating security risks in software applications. They conduct security assessments, perform code reviews, and advise development teams on best practices for securing applications against threats such as data breaches and cyberattacks. Their work helps organizations protect sensitive information and comply with industry regulations. Additionally, they may assist in developing secure coding guidelines and provide training to developers.

What are the key skills and qualifications needed to thrive as an application security consultant, and why are they important?

To thrive as an Application Security Consultant, you need a deep understanding of secure software development, vulnerability assessment, and knowledge of security frameworks, often supported by a degree in computer science and certifications like CISSP or CEH. Familiarity with tools such as Burp Suite, OWASP ZAP, static and dynamic analysis tools, and experience with secure coding practices are crucial. Strong analytical thinking, problem-solving abilities, and effective communication help consultants clearly convey risks and remediation strategies to both technical and non-technical stakeholders. These skills ensure robust application security, compliance with industry standards, and effective protection against evolving cyber threats.

What are some common challenges faced by application security consultants when working with development teams?

Application Security Consultants often encounter challenges such as bridging the gap between security best practices and fast-paced development cycles. They must effectively communicate complex security concepts to developers who may not have specialized security training, ensuring that security is integrated early without hindering productivity. Additionally, consultants need to prioritize vulnerabilities based on risk and help teams implement practical remediation strategies within project timelines. Building strong partnerships and fostering a culture of security awareness are key to overcoming these challenges.

What is the difference between Application Security Consultant vs Security Analyst?

AspectApplication Security ConsultantSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentConsulting firms, tech companies, project-basedIn-house security teams, IT departments
Primary FocusIdentifying and mitigating application vulnerabilitiesMonitoring, analyzing security threats and incidents
Industry UsageSoftware development, cybersecurity consultingFinancial, healthcare, enterprise sectors

Application Security Consultants focus on securing software applications by identifying vulnerabilities and advising on best practices. Security Analysts monitor and analyze security threats within an organization. While both roles require cybersecurity certifications and involve protecting digital assets, their daily tasks and environments differ significantly.

More about Application Security Consultant jobs

What cities are hiring for Application Security Consultant jobs?

Cities with the most Application Security Consultant job openings:

Who are the top companies hiring for Application Security Consultant jobs?

The top employers for Application Security Consultant jobs are:

What states have the most Application Security Consultant jobs?

States with the most job openings for Application Security Consultant jobs include:

What are popular job titles related to Application Security Consultant jobs?

For Application Security Consultant jobs, the most frequently searched job titles are:

Infographic showing various Application Security Consultant job openings in the United States as of September 2026, with employment types broken down into 77% Full Time, 19% Part Time, and 4% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $117,232 per year, or $56.4 per hour.

Cybersecurity Consultant Iv, Application Security (greensboro, Nc)

On-site

Other

Posted 15 days ago


Job description

Cybersecurity Consultant Iv, Application Security (greensboro, Nc)

Full-time

About the Job

The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance.

This role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations. Experience with cloud native applications, APIs, mobile applications, AI enabled applications, DevSecOps automation, and healthcare or other regulated environments is preferred.

Tech Summary

The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance.

The ideal candidate has advanced software development and application security experience using Java, Python, JavaScript, .NET, Swift, or similar technologies. The candidate should have practical experience with application security testing solutions, penetration testing tools such as Burp Suite or OWASP ZAP, and integrating security controls into CI/CD pipelines.

This role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations. Experience with cloud native applications, APIs, mobile applications, AI enabled applications, DevSecOps automation, and healthcare or other regulated environments is preferred.

Job Summary:

In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.

Essential Responsibilities:
  • Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities.
  • Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses; supporting team collaboration; and adapting to and learning from change, difficulties, and feedback.
  • Effectively communicates investigative findings to non-technical audiences.
  • Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture.
  • Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes.
  • Identifies the impact of security test plans on upstream and downstream solution components.
  • Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence and cyber security vulnerability assessment data.
  • Contributes to cyber security intellectual capital by making process or procedure improvements, conducting brown bag training sessions, and creating new training documents.
  • Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis.
  • Recommends business line or business technology team security process improvements which align with sustainable best practices, and the strategic and tactical goals of the business.
  • Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across multiple business domains.
  • Performs complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis.
  • Serves as an escalation point on issues, dependencies, and risks related to security testing.
  • Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately to highly complex technology initiatives across multiple IT domains by analyzing business and technology requirements.
  • Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems.
  • Provides insight and consultation on the development of testing scope and approach, and collaborates with cross-functional IT and business stakeholders to review the overall testing approach.
  • Validates security test scenarios across various SDLC phases (e.g., development, reproduction, production) for low- to moderately-complex projects.
  • Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams and management as appropriate.
Minimum Qualifications:
  • Minimum three (3) years software or application development experience.
  • Minimum one (1) year experience in application security (e.g., source code analysis, dynamic analysis, etc.).
  • Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum six (6) years experience in IT or a related field, including Minimum two (2) years in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement.
#J-18808-Ljbffr