Cybersecurity & Application Security Consultant

Overview

Seeking an experienced Cybersecurity & Application Security Consultant to provide ongoing security oversight for a digital platform handling sensitive user, identity, location, communication, and transaction-related data.

The role will focus on application and data security, secure architecture, codebase reviews, vulnerability identification, and security best practices, acting as an independent second pair of eyes across the technology stack. The engagement is advisory and task-driven rather than a conventional full-time security operations role, with periodic reviews and additional support as security-related requirements arise.

The ideal candidate should be able to assess an evolving product from both an engineering and security perspective, identify potential vulnerabilities or architectural weaknesses, and provide practical recommendations that the development team can implement.

Job Description

Key Responsibilities

  • Conduct periodic security and codebase reviews across application architecture and development practices.
  • Assess authentication, authorization, access controls, API security, data handling, and third-party integrations.
  • Identify vulnerabilities, security gaps, attack surfaces, and potential failure scenarios.
  • Review application architecture and recommend improvements for secure-by-design development.
  • Assess data storage, transmission, retention, encryption, secrets management, and privacy controls.
  • Support GDPR-oriented security and data protection practices, particularly around personally identifiable and sensitive user data.
  • Review development practices and provide recommendations for maintaining a secure and maintainable codebase.
  • Support vulnerability assessment, threat modelling, dependency/security scanning, and remediation planning.
  • Work with developers to explain findings and recommend practical remediation approaches.
  • Provide periodic security assessments and documentation covering identified risks, recommendations, and priority actions.

Skills & Requirements

  • Strong hands-on experience in Application Security / Cybersecurity
  • Secure Software Development Lifecycle (SSDLC)
  • Web and API Security
  • Code Review & Security Assessment
  • Authentication & Authorization
  • OAuth / JWT / Identity & Access Management
  • OWASP Top 10 / OWASP API Security
  • Vulnerability Assessment & Threat Modelling
  • Data Protection & Encryption
  • Secure Architecture
  • Dependency & Third-Party Risk Assessment
  • GDPR / Privacy-by-Design principles
  • Security Testing & Remediation

Nice to Have:

  • Experience reviewing security for consumer-facing platforms or marketplaces
  • Experience with cloud security and modern application infrastructure
  • Familiarity with CI/CD security and DevSecOps practices
  • Experience with applications handling payments, identity verification, location data, or minors' data
  • Relevant cybersecurity certifications such as CISSP, OSCP, CISM, Security+, or equivalent

Apply Now

Join Our Community

Let us know the skills you need and we'll find the best talent for you