Remote job
Lead Strategic Services Consultant (Application Security)
Job details
About this role
Role overview A Lead Strategic Services Consultant role combining hands-on DevSecOps engineering with strategic consulting, framework alignment, and security governance. The consultant leads client engagements to configure CI/CD pipelines, assess Application Security Programs against maturity frameworks, and deliver multi-year roadmaps that help organizations build and measure secure software capabilities. The work targets executive engineering and security audiences and spans assessment, roadmap design, workshop facilitation, and thought leadership.
Responsibilities - Configure application security testing (AST) tools in customer pipelines, including templates and configuration validation. - Triage AST findings surfaced through pipeline testing and assist customers in resolving them. - Lead AppSec program maturity assessments using frameworks such as BSIMM and NIST SSDF, including interviews, evidence collection, and scoring. - Develop 12–36-month strategic roadmaps with target states, resource requirements, and success metrics. - Facilitate workshops with executives, engineering, and AppSec leadership to prioritize initiatives tied to risk and compliance goals. - Deliver strategic recommendations to CISOs, CTOs, and software leadership; contribute to internal frameworks, accelerators, and thought leadership (webinars, conferences, press commentary).
Requirements - US Citizenship or Green Card with three years of US residency and ability to pass a background check. - 5–8+ years in application security, software assurance, or product security consulting. - Working knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM. - Hands-on skills across GitLab CI/CD, Python, AWS, and Grafana, paired with vulnerability management experience. - Demonstrated experience executing maturity models, capability assessments, or multi-year AppSec/DevSecOps roadmaps. - Strong client-facing communication, facilitation, and executive-level storytelling skills.
Nice to have - Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team. - Exposure to software supply chain risk management, AI/ML assurance, or DevSecOps pipeline design. - Experience functioning within secure SDLCs and certifications such as CEH, CISSP, or CISM.
Benefits and work setup - Listed pay range of $123,500–$185,000 USD. - Comprehensive benefits package including health coverage, retirement plans, paid time off, and wellness days (specific structure noted in the original listing).