Security Consultant - Penetration Testing & DevSecOps
$70.18k - $170.04kCapgemini
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more sustainable, more inclusive world.
Location
This is a remote role based in the US.
About The Job You're Considering
We are seeking a Senior Security Consultant - Penetration Testing & DevSecOps with 5-8 years of cybersecurity experience and strong expertise in application penetration testing, offensive security, DevSecOps, SSDLC, and vulnerability management. The role focuses on conducting security assessments across applications, APIs, cloud environments, and CI/CD pipelines, while collaborating with development and engineering teams to embed security throughout the software development lifecycle. The ideal candidate combines strong technical skills, a proactive security mindset, and the ability to communicate risks effectively to both technical and business stakeholders.
Your Role
Penetration Testing & Offensive Security
- Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure.
- Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities following industry-standard methodologies such as OWASP, PTES, NIST, and MITRE ATT&CK.
- Identify security vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations.
- Execute security assessments against modern architectures including microservices, containers, Kubernetes, and cloud-native applications.
- Develop proof-of-concepts to demonstrate security weaknesses and attack paths.
- Prepare detailed technical reports and executive summaries for customers and stakeholders.
DevSecOps & Secure SDLC
- Integrate security controls and testing into CI/CD pipelines.
- Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions.
- Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices.
- Participate in security architecture reviews, threat modeling exercises, and secure design assessments.
- Automate security testing and compliance validation within DevOps toolchains.
- Develop security guardrails and policy-as-code capabilities to improve software security posture.
Vulnerability Management & Security Engineering
- Perform vulnerability triage, risk prioritization, and remediation tracking.
- Support continuous security monitoring and risk assessment activities.
- Analyze emerging threats, attack techniques, and security trends to improve testing methodologies.
- Assist in development of security standards, procedures, and best practices.
- Work with engineering, cloud, and infrastructure teams to enhance organizational security posture.
Stakeholder Engagement
- Present findings and recommendations to developers, architects, engineering teams, and leadership.
- Provide security consulting throughout the software development lifecycle.
Your Skills And Experience
Education
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field.
Experience
- 5-8 years of hands-on cybersecurity experience.
- Minimum 3+ years of experience conducting application and API penetration testing.
- Experience implementing or supporting DevSecOps initiatives within CI/CD environments.
Technical Skills
- Strong understanding of:
- Web Application Security
- API Security
- Secure SDLC
- OWASP Top 10
- OWASP API Top 10
- MITRE ATT&CK
- Threat Modeling
- Vulnerability Management
- Hands-on experience with:
- Burp Suite Professional
- Nmap
- Nessus / Qualys / Tenable
- Metasploit
- Kali Linux
- Checkmarx
- Veracode
- Snyk
- SonarQube
- GitHub Actions / Azure DevOps / Jenkins
Desired Qualifications
Certifications :
One or more of the following certifications:
- OSCP (Preferred)
- CRTO
- PNPT
- CEH
- GWAPT
- GPEN
- CISSP
- CCSP
- Azure Security Engineer Associate
- AWS Security Specialty
Additional Skills :
- Experience with container security (Docker, Kubernetes).
- Experience conducting cloud penetration testing.
- Understanding of Infrastructure as Code (Terraform, CloudFormation).
- Familiarity with Red Team methodologies and adversary simulation.
- Experience with AI/LLM security testing is a plus.
- Exposure to Zero Trust Architecture and Secure-by-Design principles.
- Excellent communication, consulting, and stakeholder management skills.
The base compensation range for this role in the posted location is: $70,176- $170,040.
Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.
The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.
These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.
It is not typical for candidates to be hired at or near the top of the posted compensation range.
In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.
Capgemini offers a comprehensive, non-negotiable benefits package to all regular, full-time employees. In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include:
- Paid time off based on employee grade (A-F), defined by policy: Vacation: 12-25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave
- Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
- Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
- Life and disability insurance
- Employee assistance programs
- Other benefits as provided by local policy and eligibility
Important Notice: Compensation (including bonuses, commissions, or other forms of incentive pay) is not considered earned, vested, or payable until it becomes due under the terms of applicable plans or agreements and is subject to Capgemini’s discretion, consistent with applicable laws. The Company reserves the right to amend or withdraw compensation programs at any time, within the limits of applicable legislation.
Disclaimers
Capgemini is an Equal Opportunity Employer encouraging inclusion in the workplace. Capgemini also participates in the Partnership Accreditation in Indigenous Relations (PAIR) program which supports meaningful engagement with Indigenous communities across Canada by promoting fairness, accessibility, inclusion and respect. We value the rich cultural heritage and contributions of Indigenous Peoples and actively work to create a welcoming and respectful environment. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.
This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodation does not pose an undue hardship. Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.
Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.
Click the following link for more information on your rights as an Applicant in the United States.
Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.
- ...Security Consultant We are seeking an experienced Security Consultant to assess, design,... ...governance initiatives. ~ Familiarity with DevSecOps and secure software development... ...Docker security API security Penetration testing Threat intelligence MITRE...Suggested
- Delivering a range of security assessments, the fixed-term Security Consultant will conduct application security assessments, infrastructure penetration tests, and provide security advisory services while working remotely in the United States. Key responsibilities Conduct...SuggestedFixed term contractRemote work
$112k - $161k
...and internal wireless assessments, web and mobile applications testing, and embedded system assessments.Recognize and safely utilize attacker... ...for both technical and executive audiences.Advise clients on security practices for remediating discovered issues.Minimum...SuggestedRemote work- ...Our Unique Work: Information Security New York (ISNY) is responsible... ...threats through risk-based consultation, advice, and direction for controls... ...of security practices into DevSecOps methodology, performing application security testing and working directly on...SuggestedFull timeTemporary workPart timeShift work
- ...Cyber Security Analyst Strong understanding of cyber security processes and tools, i.e. penetration testing, scan analysis, vulnerability scans, physical security, vulnerability management Knowledge and understanding of DOD security regulations, DISA Security...SuggestedRemote work
- ...Job Title: Information Security Analyst Job Summary: We are seeking a highly motivated Information Security... ...SOC) environments. Knowledge of cloud security and DevSecOps practices. Familiarity with penetration testing and ethical hacking concepts. Understanding of...Full timeRemote work
- IoT Security Consultant - Remote (Anywhere in the U.S.) Apply for the IoT Security Consultant - Remote (Anywhere in the U.S.) role at GuidePoint... ...-fit solutions that mitigate risk. Experience in offensive testing and hardware hacking is required, and the role also requires...Remote jobFull timeFlexible hours
$75k - $110k
...About the Role The Application Security Analyst helps embed security... ...automation, continuous testing, secure configuration, and practical... ...management, and modern DevSecOps methodologies. The Details:... ...including SAST, DAST, SCA, penetration testing, secret scanning, and...Local areaImmediate startRemote workFlexible hours- ...SAP S/4HANA and related cloud solutions. The SAP S/4HANA Security Architecture Consultant will support the design, implementation and governance of... ...security architecture reviews throughout Design, Build, Test and Deploy phases. ? Conduct security risk assessments and...Immediate startWorldwide
$97.59k - $142.99k
...Position Summary:We have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will be part of the Penetration Testing and Vulnerabilities Management team. The group is an agile team that effectively...Full time- ...Security Analyst Job Location: NYC, NY (Looking for local Candidate - MUST be able to onsite interview for this role in NYC)... ...five years of cyber security and vulnerability management or penetration testing experience Experience in deploying and operating vulnerability...Contract workWork experience placementLocal area
$145k - $165k
...services company located in NY, NY is looking to hire a full time Security Analys t. This role collaborates with the Director of... ...external vendors performing vulnerability assessments and penetration testing. Ensure that all vendor reports are reviewed and actionable...Full timeWork at officeRemote work$127.2k - $246.9k
...among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate... ...our team.KPMG is currently seeking a Manager, Application Security, DevSecOps to join our Enterprise Security Services organization....H1bLocal area$143k - $224k
...talent. It all begins with you.Wells Fargo Bank N.A. seeks a Securities Quantitative Analytics Associate in New York, NY.Job Role and... ...conditions. Design and enhance analytical methodologies used in stress testing, scenario analysis, and regulatory capital exercises by...Full timeRemote work2 days per week$21 - $25 per hour
...looking for! About Us: At Metro One LPSG, we are reshaping the security industry with a dynamic, service-driven approach. We are proud... ...work in the United States. Strong, stable work history. Drug testing and background screening are required. Prior Military, Corrections...Weekly payFlexible hours- ...Manager, Information Security The Manager, Information Security will be responsible for the strategic leadership, execution,... ...mitigation plans, annual assessments, security audits, and penetration testing activities. Manages real time threat detection technologies...Local areaRemote workWeekend work
- ...Application Security Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next... ...Experience with threat modeling, secure code review, or penetration testing Background in bug bounty programs or red team/blue team exercises...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$75k - $77k
...Security Supervisor Mandarin Oriental New York is looking for a Security Supervisor to join our Security team. Are you a master... ...for our guests and colleagues by ensuring patrols & inspections/testing are being completed on each shift. Assist in the...Work at officeLocal areaShift workNight shift$60k - $80k
Overview Under the direction of the Security Operations Lead, the Security Analyst plays a key role in supporting and enhancing the... ...performs network security scanning/assessment and 3rd party penetration testing as assigned Ensures secure data migration and monitors data...Full timeRemote work- ...turn ideas into reality.We AreAccenture Security helps organizations prepare, protect,... ...Skills):Experience in IT Security Testing (e.g., penetration testing, web application security assessments... ...and assets across Strategy & Consulting, Technology, Operations, Industry X and...Full timeWork experience placementLive inWork at officeLocal areaRemote work
$110k - $135k
...technology, and trusted partnerships, we make security stronger, more effective, and easier... ..., threat briefings, and security consultations Produce high-quality documentation... ...threat detection, incident response, penetration testing, security engineering, or information...$38 - $45 per hour
Electronic Security Banking Specialist 2 Requisition Number : ELECT016139 Posted : July 15, 2026 Full-Time Locations Showing 1 location... ...Talent Acquisition Team and hiring managers. Installs, programs, tests, repairs, and services a variety of non‑routine systems and...Full timeLocal areaRemote workWork from home$75k - $95k
...the role: We are seeking an Application Security Analyst to build security into how we ship... ...into development pipelines, implement testing and runtime protections, and ensure that... ...security testing into CI/CD pipelines (DevSecOps) Assess security risks in AI/ML-enabled...Work at officeRemote workFlexible hours$160k - $180k
Technology and Information Security Risk Specialist Vice President | Second Line of Defense Position Summary The Technology and Information... ...Reviews — Lead and review risk assessments, RCSAs, control testing, issues, remediation plans, KRIs/KPIs, policies, procedures, evidence...Work at officeLocal area$34 per hour
...supervisory law enforcement officer, performs public safety, and security functions on behalf of a local unit within the conditions and... ...office. (6) Has successfully undergone the same psychological testing that is required of all full-time police officers in the municipality...Hourly payPermanent employmentFull timeSeasonal workWork at officeLocal areaTrial period$169.95k - $179.3k
Senior Information Security Analyst McKesson is an impact-driven, Fortune 10 company that... ...strategic goals. Develop and execute security test plans, validate controls, and enhance... ...environments. Vulnerability management, penetration testing, and secure architecture design....Remote work- ...Zantech is looking for a talented Information Security Analyst - SME to provide specialized... ...Monitoring and Internal Control Testing Support, Information Systems Security Officer... ...implementation Vulnerability assessment and penetration testing Security Information and Event...Contract work
- ...and Mandarin is MANDATORY given global team. Lead and Manage Security Operations: Oversee day-to-day security operations,... ...cloud, and endpoint protection. Conduct security audits and penetration testing to identify and mitigate risks. Backup and Patch Management...
- Information Security Analyst 2 Start Date: 09/01/2020 End Date: 03/01/2021 Work Location:... ...contract position open for a Web Application Penetration Tester. The primary tasks of this... ...application owners for application overview and testing strategy Setting up and running security...Contract workRemote workWork from home
$28 per hour
...Fitness) FLSA: NON-EXEMPT DEPARTMENT: HOUSING AND SERVICES - SECURITY SALARY: $28 PER HOUR SUMMARY: Perform responsible work... ...Ensure monthly, semiannual, and annual inspections and testing of all fire life safety devices, components, and fire extinguisher...Hourly payFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Consultant - Penetration Testing & DevSecOps. Be the first to apply!
- entry level information security analyst New York, NY
- junior security analyst New York, NY
- physical security consultant New York, NY
- application security analyst New York, NY
- IT security analyst New York, NY
- physical security specialist New York, NY
- network security analyst New York, NY
- network security consultant New York, NY
- security systems specialist New York, NY
- security coordinator New York, NY

