Application Security Specialist – Part-Time / Project-Based
Employment Type: Part-Time Contract
Estimated Level of Effort: Approximately 80 total hours over the duration of the project
Project Duration: Approximately 3-6 months
Work Arrangement: Primarily remote
Position Overview
Estrada Consulting, Inc. is seeking an experienced Application Security Specialist to provide part-time application security support for the design, development, testing, and deployment of a new public-sector web-based data management application.
The Application Security Specialist will work closely with the project architect, developers, database resources, QA personnel, and project manager to ensure that application and database security requirements are incorporated throughout the software development lifecycle.
The role is expected to require approximately 80 hours over the project duration, with the majority of effort occurring during solution design, security review, pre-production testing, vulnerability remediation, and production-readiness activities.
Key Responsibilities
- Review application architecture, technical designs, and security configurations for compliance with project security requirements.
- Provide security guidance during the design and development of a Microsoft-based web application and SQL Server database environment.
- Review and validate implementation of role-based access control (RBAC) and the principle of least privilege across application functions, database access, APIs, and administrative functions.
- Review user authentication and authorization controls, including federated identity, single sign-on, multi-factor authentication/two-factor authentication, password controls, and account-management processes.
- Verify appropriate security controls for internal users, administrators, developers, and authorized external partner users.
- Review application session-management controls, including inactivity timeouts and protections against session hijacking.
- Review secure storage and management of user credentials, including appropriate hashing and salting techniques.
- Review and validate encryption of data in transit and at rest, including TLS and applicable database/file encryption controls.
- Evaluate application and database audit logging, including authentication events, data access, data modifications, deletions, and configuration changes.
- Review protections that prevent unauthorized modification or deletion of security and audit logs.
- Assist with the implementation and review of alerts for suspicious activity and abnormal access patterns.
- Review data-classification and privacy controls to ensure appropriate protections are applied according to the sensitivity of project information.
- Perform or support application vulnerability scanning, security testing, authentication/authorization testing, and penetration testing.
- Analyze identified vulnerabilities, assess severity and risk, and work with developers to recommend appropriate remediation.
- Perform follow-up validation and re-testing of security findings following remediation.
- Review application APIs, database connections, cloud integrations, and file-upload functionality for common security weaknesses.
- Participate in pre-production security reviews and provide security input regarding production readiness.
- Assist the project team in documenting applicable application-security controls, configurations, findings, remediation activities, and security test results.
- Provide security-related input for technical documentation and knowledge-transfer activities.
Required Qualifications
Preferred Qualifications
- Experience with Microsoft .NET / C# web applications.
- Experience securing Microsoft SQL Server environments.
- Experience with Microsoft Azure application or security services.
- Experience with Microsoft identity technologies such as Microsoft Entra ID/Azure Active Directory, federated identity, SSO, and MFA.
- Experience working with California State government security standards, including State Administrative Manual (SAM) Section 5300.
- Familiarity with OWASP Top 10, secure coding standards, and secure SDLC practices.
- Experience with application-security tools used for static/dynamic analysis or vulnerability scanning.
- Experience conducting security assessments for government or other regulated environments.
- Relevant security certification such as CISSP, CSSLP, Security+, CEH, GIAC, or equivalent is desirable but not required.
Expected Project Activities
We need somebody who can stay available periodically through the project with approx 80-hours of service.
Their involvement would most likely look something like:
Design phase: security requirements/design review and RBAC/authentication architecture.
Development phase: periodic review of application, database, API, encryption, audit, and identity controls.
Testing phase: vulnerability/security testing, penetration-testing support, authentication/authorization testing, findings review, and remediation verification.
Pre-production/deployment: final security validation and production-readiness review.