Summary
GuidePoint Security provides cybersecurity expertise, solutions, and services that help organizations identify threats, optimize resources, and minimize risk. The Application Security Consultant will deliver application security assessments and related services across web, mobile, thick client, AI/LLM, and agentic applications, while developing assessment capabilities, translating findings into remediation strategies, and supporting research and client relationships.
Responsibilities
- Deliver Application Security services, including but not limited to Application Security Assessments for various application types (web, mobile, AI, thick client), Threat Modeling, and Source Code Reviews
- Perform AI/LLM and Agentic Application Security Assessments, including prompt injection testing, model/guardrail bypass, excessive agency abuse, tool-calling exploitation, RAG poisoning, and other attacks mapped to the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications
- Assess agentic AI architectures (e.g., LangChain, CrewAI, AutoGPT, MCP-based agents, Salesforce Agentforce) for excessive agency, insecure tool/function integrations, goal manipulation, cross-agent/cross-prompt injection, and unsafe autonomy boundaries
- Author assessment deliverables that are tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies
- Build and extend AI-driven tooling to support assessments — including custom agents, agent skills, tool integrations, and full automation harnesses that leverage LLMs to improve testing coverage, consistency, and efficiency — while applying hands-on AI/LLM knowledge (prompt engineering, model behavior, context/window management, retrieval-augmented generation, MCP servers/tools) both to test AI systems and to build internal AI-assisted capabilities
- Utilize automation, orchestration, scripting, and AI-assisted tooling to reduce manual processes, improving overall efficiency while also enabling new capabilities to meet the rapidly changing needs of our clients
- Contribute to Application Security research projects, including emerging AI and agentic threat research, and support marketing initiatives through activities such as speaking at industry conferences, authoring blog articles and whitepapers, delivering webinars, and contributing to security tools
- Foster client relationships by providing support and information, and perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry, including the fast-evolving AI/LLM and agentic security landscape
- Maintain a strong desire to learn, adapt, and improve along with a rapidly-growing company, and perform other duties as assigned
Skills
- * High School Diploma + 5 years of experience OR Bachelor's Degree (BS/BA) + 2 years of experience OR Master's Degree (MS/MA)
- * Minimum of two (2) years of experience performing Application Security assessments
- * Minimum of one (1) year of experience in an enterprise-level consulting services role
- * Experience with testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, OpenSSL, etc
- * Experience reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#
- * Hands-on experience testing AI/LLM-powered applications and agentic AI systems (chatbots, RAG pipelines, autonomous/multi-agent workflows) for prompt injection, data leakage, excessive agency, insecure output handling, and tool/function-calling abuse
- * Familiarity with the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, and practical experience testing against them
- * General AI fluency and practical usage, including working with LLM APIs/SDKs (e.g., OpenAI, Anthropic, Bedrock, Azure OpenAI) and modern AI-assisted development workflows
- * Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- * Up to 20% travel
- * Sedentary work
- * Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
- * Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
- * Over four (4+) combined years of IT and information security experience
- * Internal operational (non-consulting) experience is strongly preferred, particularly internal operational DevSecOps experience
- * Experience building AI agents, agent skills, custom tools, and full AI-assisted testing harnesses (e.g., MCP servers, LLM-orchestrated automation, agentic workflows) to support or scale security assessments
- * InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience, is strongly preferred
- * Standard industry certifications
Qualifications
Must Haves
- * High School Diploma + 5 years of experience OR Bachelor's Degree (BS/BA) + 2 years of experience OR Master's Degree (MS/MA)
- * Minimum of two (2) years of experience performing Application Security assessments
- * Minimum of one (1) year of experience in an enterprise-level consulting services role
- * Experience with testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, OpenSSL, etc
- * Experience reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#
- * Hands-on experience testing AI/LLM-powered applications and agentic AI systems (chatbots, RAG pipelines, autonomous/multi-agent workflows) for prompt injection, data leakage, excessive agency, insecure output handling, and tool/function-calling abuse
- * Familiarity with the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, and practical experience testing against them
- * General AI fluency and practical usage, including working with LLM APIs/SDKs (e.g., OpenAI, Anthropic, Bedrock, Azure OpenAI) and modern AI-assisted development workflows
- * Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- * Up to 20% travel
- * Sedentary work
- * Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
- * Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
Nice to Haves
- * Over four (4+) combined years of IT and information security experience
- * Internal operational (non-consulting) experience is strongly preferred, particularly internal operational DevSecOps experience
- * Experience building AI agents, agent skills, custom tools, and full AI-assisted testing harnesses (e.g., MCP servers, LLM-orchestrated automation, agentic workflows) to support or scale security assessments
- * InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience, is strongly preferred
- * Standard industry certifications
Benefits
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option