Security Consultant with security assessments/control review and NIST exp. (Remote)

LTM

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in information security focused on application security
  • Experience in conducting security design reviews and threat modeling for enterprise environments
  • Strong knowledge of security control frameworks like NIST, CIS, ISO 27001
  • Familiarity with fullstack application security concepts such as encryption and API security
  • Experience working with application owners and vendors in large-scale environments
  • Excellent written communication skills for documentation in Word and Excel
  • Highly organized with project management skills, preferably using Asana

Responsibilities

  • Conduct application security assessments across SaaS, on-premises, and IaaS environments
  • Perform full-stack security assessments focusing on frontend and backend security
  • Evaluate security controls against application capabilities and trust boundaries
  • Document security findings and recommendations in standardized templates
  • Track and manage critical security controls for each application
  • Engage with application owners to assess security postures
  • Provide clear mitigation guidance for identified security gaps

Benefits

  • Participation in ongoing professional development and training
  • Opportunity to work in a collaborative and cross-functional team environment
  • Engagement with cutting-edge security technologies and frameworks
  • Ability to influence security practices across various applications
  • Work directly with stakeholders in a dynamic business environment
Full Job Description
Role description

Job Description

Job Title Application Security Assessment

Location : New York , NY

Key Responsibilities

Application Security Assessments

Conduct end to end security design reviews and related validationverification tasks for 50 applications across SaaS onpremises and IaaS environments.

Conduct fullstack security assessments and provide control requirements based on the applications activity scope capabilities and boundaries with focus areas and other areas as applicable with context to the application being assessed.

Frontend Clientside security.

Backend Platform security.

Identity Access Management IAM.

Encryption in transit and at rest.

Network security.

Data security.

Logging monitoring and SIEM integration.

Evaluate security controls against each applications activity scope capabilities and trust boundaries.

Document findings control gaps and recommendations in standardized Word or Excel templates

Control Management Tracking

Identify track and maintain the status of critical security controls for each application in scope

Apply security standards and control frameworks eg NIST CIS ISO 27001 to rationalize and map control requirements

Maintain accurate and uptodate deliverable tracking in Asana across all active reviews

Stakeholder Engagement

Identify and engage application owners using the enterprise application management portfolio or through direct outreach

Interview application owners and obtain necessary access to assess current security posture

Provide clear prioritized mitigation guidance for identified gaps aligned to enterprise policies and standards

Engage thirdparty application vendors as required to support assessment activities

Serve as a direct point of contact for application owners and crossfunctional enterprise teams seeking guidance or information

Reporting Cadence

Participate in weekly checkins to report on assessment progress blockers and completed reviews

Report directly to the VP of Information Security

Communicate findings and recommendations in a clear businessappropriate manner to both technical and nontechnical stakeholders

Required Qualifications

5 years of experience in information security with a focus on application security architecture or security assessments

Demonstrated experience conducting security design reviews or threat modeling for enterprise applications SaaS IaaS and onpremises

Strong working knowledge of security control frameworks NIST CSF NIST SP 80053 CIS Controls ISO 27001

Familiarity with fullstack application security concepts including authentication authorization encryption API security network segmentation and data protection

Experience working directly with application owners product teams and vendors in an enterprise environment

Strong written communication skills ability to produce clear structured assessment documentation in Word and Excel

Highly organized with demonstrated ability to manage multiple concurrent assessments and track deliverables Asana or similar project management tools

Preferred Qualifications

Relevant certifications CISSP CCSP CISM CSSLP or equivalent

Familiarity with cloud security principles across AWS Azure or GCP

Experience applying security standards to vendorthirdparty risk assessments

Prior experience working within media entertainment or largescale enterprise environments

What Success Looks Like

By the end of this engagement you will have delivered

50 completed security design reviews and validationverification tasks with documented control assessments and findings

A maintained uptodate control tracking register across all applications in scope

Mitigation guidance provided to application owners with clear actionable remediation steps

All deliverables logged and tracked in Asana with review documentation available in Word or Excel

Similar Jobs

More Jobs at LTM

More Information Technology Jobs

Find similar Security Consultant with security assessments/control review and NIST exp. (Remote) jobs: