About The Position

We're looking for a Web Security Consultant who can help us build secure websites from the ground up. Security isn't something that should be addressed at the end of a project—it's something that should be considered throughout the entire development lifecycle. We're looking for someone who can help us establish best practices, identify potential risks before they become problems, and create repeatable standards that every project can follow. In this role, you'll work closely with our development team to review websites and web applications, ensure they meet current security standards, and build practical processes that improve consistency across every project. Our web environment is primarily built on WordPress, alongside other modern web technologies. Because of this, strong experience securing WordPress websites, plugins, themes, hosting environments, and deployment workflows is a significant advantage. Beyond identifying vulnerabilities, you'll help create documentation, checklists, and security guidelines that become part of our standard development workflow.

Requirements

  • Web application security principles and secure development practices.
  • Familiarity with the OWASP Top 10 and common web application vulnerabilities.
  • Security reviews for modern web applications and websites.
  • Strong experience securing WordPress websites, including themes, plugins, user roles, hosting environments, and update strategies.
  • Authentication, authorization, session management, and access control best practices.
  • HTTPS, SSL/TLS, HTTP security headers, and Content Security Policy (CSP).
  • Security testing tools and vulnerability assessment methodologies.
  • Experience reviewing websites built with modern CMS platforms and JavaScript frameworks.
  • Strong documentation skills and experience developing internal standards or technical playbooks.
  • Excellent communication skills and the ability to explain technical concepts to both technical and non-technical stakeholders.

Nice To Haves

  • Penetration testing or vulnerability assessments.
  • Cloud hosting platforms such as AWS, Azure, or Google Cloud.
  • Web application firewalls (WAF) and CDN security.
  • DevSecOps practices and CI/CD security integration.
  • Compliance frameworks such as SOC 2, ISO 27001, GDPR, or PCI DSS.
  • Deep expertise in WordPress security, including hardening, plugin vulnerability management, hosting security, and performance/security best practices.
  • Shopify, Webflow, headless CMS, or modern JavaScript framework security.
  • Security automation and monitoring tools.

Responsibilities

  • Reviewing websites and web applications to ensure they follow current web security best practices.
  • Conducting security reviews for WordPress websites and other web applications, identifying platform-specific risks and recommending practical remediation strategies.
  • Identifying security vulnerabilities and recommending practical remediation strategies.
  • Performing security reviews throughout the development lifecycle rather than only before launch.
  • Developing a standardized security checklist that becomes part of every new website project.
  • Creating internal documentation and security best practices for developers and project teams.
  • Advising developers on secure coding practices and common web application vulnerabilities.
  • Helping establish secure deployment, hosting, authentication, and access management standards.
  • Recommending security best practices for WordPress core updates, plugin management, user permissions, backups, and hosting configurations.
  • Working with project managers and technical teams to ensure security requirements are incorporated into project planning.
  • Staying current on evolving security threats, frameworks, and industry standards.
  • Supporting periodic security audits and continuous improvements across existing client websites.

Benefits

  • Security is a critical part of delivering quality work—not an afterthought.
  • You'll help establish the standards and processes that shape how every website is built, giving our developers the tools and guidance they need to deliver secure, reliable solutions from day one.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service