Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

DirectDefense

Application Security Consultant

Career Insights for Vulnerability Analyst / Penetration Tester

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Colorado data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.

$107,473 / year median in Colorado

+6% projected growth

Explore Career

Job Description

Are you passionate about application security and ready to make an immediate impact in a contract role? We are seeking a motivated Application Security Consultant with experience in software development, DevOps, or software quality assurance—or a strong foundation in application security. In this role, you will assess customer applications, identify and validate vulnerabilities, leverage innovative security tools, and recommend practical remediation strategies.
Responsibilities:
Conduct thorough analysis to identify and exploit vulnerabilities in customer applications. Collaborate with development teams to creatively remediate identified vulnerabilities and enhance application security. Perform dynamic testing and static code reviews to identify security vulnerabilities and weaknesses. Utilize industry-leading tools, with a focus on application testing workspaces such as Burp Suite. Stay abreast of the latest developments in application security, tools, and methodologies such as
OWASP ASVS
Qualifications:
1-3 years of hands-on experience in network/infrastructure security and penetration testing. Bachelor's degree in Computer Science, Engineering, Math, or a related field (or equivalent hands-on experience, classroom project work, or internship). Strong understanding of application security principles and common vulnerabilities. Experience in performing dynamic and static code reviews. Familiarity with vulnerability scanning tools, specifically Burp Suite. Excellent written and verbal communication skills, with the ability to convey complex security topics clearly and concisely to diverse audiences. Experience in automated and manual application testing is a big plus.
Preferred Skills:
Certifications such as OSCP, BSCP, OSWE, GWAPT or related offensive security certifications are a strong plus. Knowledge of common web application vulnerabilities and exploitation techniques. Understanding of cryptography, authentication, and authorization mechanisms. Excellent problem-solving skills and a proactive approach to addressing security concerns. Effective communication and collaboration skills to work with cross-functional teams. Experience with automated and manual application testing is a significant plus. AWS experience is a big plus. A little about DirectDefense Since coming together in 2011 to form DirectDefense, our team has been committed to offering Cybersecurity defense strategies that are unmatched in the industry. Whether we are performing assessments of networks, platforms, and applications or applying managed services to improve your organization's security posture, we are focused on providing world-class services that don't just work-they work for you.
OUR MISSION
We establish partnerships with our clients based on trust and results. We leverage our deep industry knowledge and expertise to identify and remediate blind spots in your security program, provide meaningful visibility of your entire enterprise, and align your organization with security best practices and compliance standards.
OUR VISION
We aim to secure organizations across all industries against advanced threats and attacks in today's world. Partnering with organizations, we provide unmatched information security services designed to improve your overall security posture, close gaps, and continuously track vulnerabilities through ongoing education and support.