Job Title: Senior Cybersecurity Consultant
Location: Houston, TX
Contract: 6 Months
Key Responsibilities:
Lead security assessments and vulnerability management across the full portfolio of ~90 .NET-based web applications (customer-facing and internal)
Design and implement Web Application Firewall (WAF) policies and DDoS mitigation for customer-facing platforms
Perform application security reviews of .NET/full-stack codebases; embed SAST/DAST tooling into CI/CD pipelines
Drive secure Software Development Lifecycle (SDLC) and DevSecOps practices in partnership with .NET engineering teams
Monitor, detect, and respond to cyber threats targeting public-facing infrastructure
Conduct penetration testing and coordinate remediation across both customer-facing and internal applications, prioritized by risk
Ensure compliance with NERC CIP and other utility-sector regulatory requirements, including access management and incident response obligations
Evaluate and harden cloud infrastructure security (AWS/Azure) supporting the application portfolio
Apply Zero Trust principles across internal and customer-facing environments
Partner with IT, application, and infrastructure teams to embed security best practices
Prepare security reports and risk assessments for leadership
Required Skills & Experience:
8+ years of experience in cybersecurity, with a strong focus on application and web security
Hands-on application security experience with .NET/full-stack environments (secure coding review, SAST/DAST integration)
Strong hands-on experience with WAF, DDoS mitigation, and vulnerability management tools
Solid understanding of secure SDLC and DevSecOps practices
Experience with cloud security (AWS and/or Azure)
Working knowledge of NERC CIP or other energy/utility sector compliance frameworks
Scripting ability (Python, PowerShell, or Bash) for automation of security tasks
Relevant certifications preferred: CISSP, CEH, OSCP, or equivalent
Strong communication skills to work with both technical teams and leadership
Preferred Qualifications:
- Prior experience in the energy/utility sector, particularly with OT/IT convergence awareness
- Experience securing high-traffic, customer-facing digital platforms alongside internal business applications
- Familiarity with SIEM tools and incident response processes
- Zero Trust architecture implementation experience