Logo for GuidePoint Security

Senior Application Security Engineer - Southeast region (Remote)

Key Facts

Remote From: 
Full time
Senior (5-10 years)
English

Other Skills

  • Communication
  • Collaboration
  • Problem Solving

Roles & Responsibilities

  • 5+ years in application security, with demonstrated experience building, scaling, or leading an AppSec program
  • Proficiency with the implementation, operationalization, and troubleshooting of tools across the AppSec landscape (SAST, DAST, SCA, API Security, secrets management)
  • Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities identified by web application scanning tools
  • Excellent written and verbal communication skills

Requirements:

  • Leading AppSec program assessments to evaluate current state, identify gaps, and help clients prioritize remediation efforts
  • Designing pragmatic security workflows, processes, tooling integrations, and developer friendly practices
  • Getting hands-on when needed: implementing SAST/SCA/DAST/API tooling, configuring CI/CD security gates
  • Delivering polished client work, producing clear assessments, actionable roadmaps, implementation guides, and executive communications

Job description

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

The Role

We’re a specialized AppSec team providing advisory, engineering, and fractional security support to development teams. We’re looking for a senior consultant who knows what good looks like and has the expertise to help clients get there. You’ll work across a diverse portfolio of client engagements, helping organizations mature their application security programs or optimize what they’ve already built. Some clients need strategic roadmaps and executive alignment, while others need someone to roll up their sleeves and build alongside their teams. Most need both. You’ve built an AppSec program before. You understand the gaps that inevitably appear, the organizational friction that slows progress, and the practical approaches that actually get engineering teams moving in the right direction. You can hold your own with a CISO discussing risk posture and business impact, then walk into a sprint planning meeting and earn immediate credibility with developers.

What You’ll Be Doing

  • Leading AppSec program assessments to evaluate current state, identify gaps, and help clients prioritize remediation efforts based on risk, resources, and organizational readiness
  • Designing pragmatic security workflows, processes, tooling integrations, and developer friendly practices that engineering teams will actually adopt
  • Getting hands-on when needed: implementing SAST/SCA/DAST/API tooling, configuring CI/CD security gates, building threat models, and conducting architecture reviews
  • Navigating organizational complexity by helping clients work through the messy middle: tool sprawl, low adoption rates, competing priorities, technical debt, and cross-functional alignment challenges
  • Delivering polished client work, producing clear assessments, actionable roadmaps, implementation guides, and executive communications that drive decision-making
  • Serving as a strategic advisor and hands-on partner, adapting your approach to each client’s culture, maturity, and goals

What We’re Looking For

Required:

  • 5+ years in application security, with demonstrated experience building, scaling, or leading an AppSec program
  • Proficiency with the implementation, operationalization, and troubleshooting of tools across the AppSec landscape (SAST, DAST, SCA, API Security, secrets management)
  • Comfortable operating at the strategic level (program design, roadmaps, risk prioritization) and the tactical level (hands-on implementation, tool configuration, code review)
  • Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities identified by web application scanning tools
  • Excellent written and verbal communication skills (you can translate technical findings into business risk for executives, and explain security requirements to developers)

Nice to have:

  • Prior consulting or client-facing experience, scoping engagements, managing expectations and delivering clean work
  • Operational DevSecOps experience
  • Security certifications (CSSLP, OSCP, GWAPT, or similar)
  • Experience with cloud-native security (AWS, Azure, GCP) and container/Kubernetes security

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

 

Security Engineer Related jobs

Other jobs at GuidePoint Security

We help you get seen. Not ignored.

We help you get seen faster — by the right people.

🚀

Auto-Apply

We apply for you — automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.