Haystack
← Back to Jobs
Administrative
ES

Application Security / Web Security Consultnat

Estuate Inc.Houston, TX🇺🇸United StatesPosted 28 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Houston, TX, United States
Posted
20 hours ago

Job Description

Job Title: Senior Cybersecurity Consultant - Application Security / Web Security

Location: Houston, TX (Onsite)

Contract

Key Responsibilities:

  • Lead security assessments and vulnerability management across the full portfolio of ~90 .NET-based web applications (customer-facing and internal)
  • Design and implement Web Application Firewall (WAF) policies and DDoS mitigation for customer-facing platforms
  • Perform application security reviews of .NET/full-stack codebases; embed SAST/DAST tooling into CI/CD pipelines
  • Drive secure Software Development Lifecycle (SDLC) and DevSecOps practices in partnership with .NET engineering teams
  • Monitor, detect, and respond to cyber threats targeting public-facing infrastructure
  • Conduct penetration testing and coordinate remediation across both customer-facing and internal applications, prioritized by risk
  • Ensure compliance with NERC CIP and other utility-sector regulatory requirements, including access management and incident response obligations
  • Evaluate and harden cloud infrastructure security (AWS/Azure) supporting the application portfolio
  • Apply Zero Trust principles across internal and customer-facing environments
  • Partner with IT, application, and infrastructure teams to embed security best practices
  • Prepare security reports and risk assessments for leadership

Required Skills & Experience:

  • 8+ years of experience in cybersecurity, with a strong focus on application and web security
  • Hands-on application security experience with .NET/full-stack environments (secure coding review, SAST/DAST integration)
  • Strong hands-on experience with WAF, DDoS mitigation, and vulnerability management tools
  • Solid understanding of secure SDLC and DevSecOps practices
  • Experience with cloud security (AWS and/or Azure)
  • Working knowledge of NERC CIP or other energy/utility sector compliance frameworks
  • Scripting ability (Python, PowerShell, or Bash) for automation of security tasks
  • Relevant certifications preferred: CISSP, CEH, OSCP, or equivalent
  • Strong communication skills to work with both technical teams and leadership

Preferred Qualifications:

  • Prior experience in the energy/utility sector, particularly with OT/IT convergence awareness
  • Experience securing high-traffic, customer-facing digital platforms alongside internal business applications
  • Familiarity with SIEM tools and incident response processes
  • Zero Trust architecture implementation experience

Similar jobs