Security Consultant with security assessments/control review and NIST exp. (Remote)

LTM

$110K — $130K *
US-AnywhereRemote in New York, NY
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in information security focused on application security assessments.
  • Experience with security design reviews and threat modeling for enterprise applications.
  • Knowledge of security frameworks like NIST CSF, NIST SP 800-53, and ISO 27001.
  • Understanding of full-stack application security concepts including encryption and data protection.
  • Proven track record in engagement with application owners and product teams.
  • Strong written communication and documentation skills needed for reporting.
  • Ability to manage multiple assessments using project management tools like Asana.

Responsibilities

  • Conduct security assessments for 50 applications across various environments.
  • Perform end-to-end security design reviews and validations.
  • Evaluate security controls based on application activity and trust boundaries.
  • Document findings and control gaps using standardized templates.
  • Track and manage critical security controls for applications.
  • Engage with application owners and vendors to assess security postures.
  • Report assessment progress and findings to stakeholders, including the VP of Information Security.

Benefits

  • Collaborative work environment with cross-functional teams.
  • Opportunity to work with cutting-edge security technologies.
  • Engagement with a diverse range of applications and stakeholders.
  • Professional development opportunities in security practices.
  • Access to the latest security tools and frameworks.
Full Job Description
Role description

Job Description

Job Title Application Security Assessment

Location : New York , NY

Key Responsibilities

Application Security Assessments

Conduct end to end security design reviews and related validationverification tasks for 50 applications across SaaS onpremises and IaaS environments.

Conduct fullstack security assessments and provide control requirements based on the applications activity scope capabilities and boundaries with focus areas and other areas as applicable with context to the application being assessed.

Frontend Clientside security.

Backend Platform security.

Identity Access Management IAM.

Encryption in transit and at rest.

Network security.

Data security.

Logging monitoring and SIEM integration.

Evaluate security controls against each applications activity scope capabilities and trust boundaries.

Document findings control gaps and recommendations in standardized Word or Excel templates

Control Management Tracking

Identify track and maintain the status of critical security controls for each application in scope

Apply security standards and control frameworks eg NIST CIS ISO 27001 to rationalize and map control requirements

Maintain accurate and uptodate deliverable tracking in Asana across all active reviews

Stakeholder Engagement

Identify and engage application owners using the enterprise application management portfolio or through direct outreach

Interview application owners and obtain necessary access to assess current security posture

Provide clear prioritized mitigation guidance for identified gaps aligned to enterprise policies and standards

Engage thirdparty application vendors as required to support assessment activities

Serve as a direct point of contact for application owners and crossfunctional enterprise teams seeking guidance or information

Reporting Cadence

Participate in weekly checkins to report on assessment progress blockers and completed reviews

Report directly to the VP of Information Security

Communicate findings and recommendations in a clear businessappropriate manner to both technical and nontechnical stakeholders

Required Qualifications

5 years of experience in information security with a focus on application security architecture or security assessments

Demonstrated experience conducting security design reviews or threat modeling for enterprise applications SaaS IaaS and onpremises

Strong working knowledge of security control frameworks NIST CSF NIST SP 80053 CIS Controls ISO 27001

Familiarity with fullstack application security concepts including authentication authorization encryption API security network segmentation and data protection

Experience working directly with application owners product teams and vendors in an enterprise environment

Strong written communication skills ability to produce clear structured assessment documentation in Word and Excel

Highly organized with demonstrated ability to manage multiple concurrent assessments and track deliverables Asana or similar project management tools

Preferred Qualifications

Relevant certifications CISSP CCSP CISM CSSLP or equivalent

Familiarity with cloud security principles across AWS Azure or GCP

Experience applying security standards to vendorthirdparty risk assessments

Prior experience working within media entertainment or largescale enterprise environments

What Success Looks Like

By the end of this engagement you will have delivered

50 completed security design reviews and validationverification tasks with documented control assessments and findings

A maintained uptodate control tracking register across all applications in scope

Mitigation guidance provided to application owners with clear actionable remediation steps

All deliverables logged and tracked in Asana with review documentation available in Word or Excel

Similar Jobs

More Jobs at LTM

More Information Technology Jobs

Find similar Security Consultant with security assessments/control review and NIST exp. (Remote) jobs: