Estrada Consulting Incorporated

Application Security Specialist -Part Time (Ref: 5855)

Remote•United States•Contract
$70 - $75 hourly
About the Job

Application Security Specialist – Part-Time / Project-Based

Employment Type: Part-Time Contract
Estimated Level of Effort: Approximately 80 total hours over the duration of the project
Project Duration: Approximately 3-6 months
Work Arrangement: Primarily remote 

Position Overview

Estrada Consulting, Inc. is seeking an experienced Application Security Specialist to provide part-time application security support for the design, development, testing, and deployment of a new public-sector web-based data management application.
The Application Security Specialist will work closely with the project architect, developers, database resources, QA personnel, and project manager to ensure that application and database security requirements are incorporated throughout the software development lifecycle.
The role is expected to require approximately 80 hours over the project duration, with the majority of effort occurring during solution design, security review, pre-production testing, vulnerability remediation, and production-readiness activities.

Key Responsibilities

  • Review application architecture, technical designs, and security configurations for compliance with project security requirements.
  • Provide security guidance during the design and development of a Microsoft-based web application and SQL Server database environment.
  • Review and validate implementation of role-based access control (RBAC) and the principle of least privilege across application functions, database access, APIs, and administrative functions.
  • Review user authentication and authorization controls, including federated identity, single sign-on, multi-factor authentication/two-factor authentication, password controls, and account-management processes.
  • Verify appropriate security controls for internal users, administrators, developers, and authorized external partner users.
  • Review application session-management controls, including inactivity timeouts and protections against session hijacking.
  • Review secure storage and management of user credentials, including appropriate hashing and salting techniques.
  • Review and validate encryption of data in transit and at rest, including TLS and applicable database/file encryption controls.
  • Evaluate application and database audit logging, including authentication events, data access, data modifications, deletions, and configuration changes.
  • Review protections that prevent unauthorized modification or deletion of security and audit logs.
  • Assist with the implementation and review of alerts for suspicious activity and abnormal access patterns.
  • Review data-classification and privacy controls to ensure appropriate protections are applied according to the sensitivity of project information.
  • Perform or support application vulnerability scanning, security testing, authentication/authorization testing, and penetration testing.
  • Analyze identified vulnerabilities, assess severity and risk, and work with developers to recommend appropriate remediation.
  • Perform follow-up validation and re-testing of security findings following remediation.
  • Review application APIs, database connections, cloud integrations, and file-upload functionality for common security weaknesses.
  • Participate in pre-production security reviews and provide security input regarding production readiness.
  • Assist the project team in documenting applicable application-security controls, configurations, findings, remediation activities, and security test results.
  • Provide security-related input for technical documentation and knowledge-transfer activities.

Required Qualifications

  • 5+ years of experience in application security, cybersecurity, information security, or secure software development.
  • Hands-on experience evaluating the security of web-based applications.
  • Experience with application security controls involving:
    • Authentication and authorization
    • Role-Based Access Control (RBAC)
    • Least-privilege access
    • Multi-factor authentication
    • Secure session management
    • Encryption in transit and at rest
    • Audit logging and monitoring
  • Experience performing or supporting vulnerability assessments, vulnerability scanning, and penetration testing of web applications.
  • Experience identifying application vulnerabilities and working with development teams to remediate security findings.
  • Knowledge of secure application-development practices and common web-application vulnerabilities.
  • Experience reviewing security controls for databases, APIs, web services, or cloud-hosted application components.
  • Working knowledge of NIST security controls/frameworks, particularly NIST SP 800-53.
  • Ability to document security findings, risks, recommendations, and remediation results.
  • Ability to work collaboratively with application developers, architects, database personnel, QA/testing staff, and project management.

Preferred Qualifications

  • Experience with Microsoft .NET / C# web applications.
  • Experience securing Microsoft SQL Server environments.
  • Experience with Microsoft Azure application or security services.
  • Experience with Microsoft identity technologies such as Microsoft Entra ID/Azure Active Directory, federated identity, SSO, and MFA.
  • Experience working with California State government security standards, including State Administrative Manual (SAM) Section 5300.
  • Familiarity with OWASP Top 10, secure coding standards, and secure SDLC practices.
  • Experience with application-security tools used for static/dynamic analysis or vulnerability scanning.
  • Experience conducting security assessments for government or other regulated environments.
  • Relevant security certification such as CISSP, CSSLP, Security+, CEH, GIAC, or equivalent is desirable but not required.

Expected Project Activities

We need somebody who can stay available periodically through the project with approx 80-hours of service.
Their involvement would most likely look something like:
Design phase: security requirements/design review and RBAC/authentication architecture.
Development phase: periodic review of application, database, API, encryption, audit, and identity controls.
Testing phase: vulnerability/security testing, penetration-testing support, authentication/authorization testing, findings review, and remediation verification.
Pre-production/deployment: final security validation and production-readiness review.