Senior Security Consultant, Application Security

Visa Hunt

Brasil

Híbrido

BRL 387 000 - 903 000

Tempo integral

Há 13 dias
Gerador de candidaturas

Uma candidatura completa num minuto — currículo e carta de apresentação personalizados, prontos a enviar.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Remote or office work flexibility
Competitive compensation and growth

Resumo da oferta

IOActive seeks a Senior Consultant, Application Security to lead high‑impact code reviews, pen tests, and threat modeling for enterprise clients. You will drive engagement delivery, mentor junior staff, and shape secure development practices through SDLC advisory work.

You will collaborate with cross‑functional teams, present findings to engineers and security leaders, and contribute to IOActive’s security research and tooling efforts.

Qualificações

  • 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review.
  • Hands-on engagement across AppSec disciplines — code review, application penetration testing, threat modeling, or SDLC consulting.
  • Deep code review expertise in at least two of: JavaScript/TypeScript, Python, Java, C#/ASP.NET, C/C++, Rust, GoLang.

Responsabilidades

  • Lead manual source code reviews on complex production codebases spanning web apps, mobile backends, APIs, and embedded systems.
  • Perform application penetration testing across web, API, and mobile targets.
  • Provide threat modeling and SDLC advisory support to clients and teams.

Conhecimentos

Code review
Application security
Penetration testing
Threat modeling
SDLC advisory

Formação académica

Bachelor's degree or equivalent experience
OSCP/OSWE/GWAPT/CSSLP/GWEB or similar certifications

Ferramentas

OWASP ASVS
NIST SSDF
BSIMM/SAMM

Descrição da oferta de emprego

OUR MISSION UNITES US

"Making the world a safer and more secure place."

It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn\'t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.

About IOActive:

IOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.

About the Role

The Senior Consultant, Application Security is a senior technical practitioner in IOActive’s Application Security practice, with secure code review as the central specialty.[AM1][AM2] The role centers on deep manual code audit work across web and systems languages, paired with application penetration testing, threat modeling, and Secure Development Lifecycle (SDLC) advisory engagements.

Code review engagements at IOActive span the full landscape: source code reviews on production codebases for enterprise web applications, mobile backends, embedded systems, and cryptographic implementations; application penetration testing against web, API, and mobile targets; threat modeling for new product designs; and SDLC advisory work helping clients integrate security into their development processes. The Senior Consultant brings particular depth in code review and broad competence across the adjacent work.

What You\'ll Do
Engagement Delivery — Code Review (primary, ~50–60%)
  • Lead manual source code reviews on complex production codebases spanning web applications, mobile backends, APIs, and embedded systems
  • Identify vulnerability classes ranging from common (injection, authentication and authorization flaws, SSRF, XSS, deserialization) to nuanced (race conditions, deserialization gadgets, cryptographic implementation flaws, business logic vulnerabilities, architectural weaknesses)
  • Author findings reports that developers can act on: clear remediation guidance, working proof-of-concepts where appropriate, and architectural recommendations beyond the immediate fix
  • Lead client developer workshops to explain findings and patterns, helping teams build security resilience rather than just fixing the listed issues
Engagement Delivery — Adjacent Application Security Wor
  • Application penetration testing across web, API, and mobile targets, particularly where engagements span code review and dynamic testing
  • Threat modeling on new product designs and existing systems using STRIDE, attack trees, or equivalent frameworks
  • Secure design reviews of architecture, authentication systems, cryptographic implementations, and inter-service communicatio
  • SDLC advisory engagements: helping clients integrate code review, threat modeling, and security testing into their development lifecycle (CI/CD, pull-request workflows, developer training)
Client Engagement
  • Serve as the senior technical voice in engagement status meetings, client workshops, technical deep-dives, and developer training sessions
  • Build trusted technical relationships with client engineering leadership, AppSec teams, and security architects
  • Translate technical findings for two distinct audiences: developers who need to fix the issue, and security leadership who need to understand the business risk and pattern
  • Support pre-sales conversations with technical credibility — scoping calls, capability discussions, and proposal input
Practice Contribution and Mentorship
  • Mentor junior and mid-level consultants in code review methodology, vulnerability research, and client engagement — even without direct reporting authority
  • Contribute to IOActive’s code review playbooks, tooling, methodologies, and report templates
  • Identify opportunities to extend IOActive’s AppSec capability — new tooling, target stacks, research directions, or service offerings
  • Collaborate with adjacent practices (Red Team, Hardware/Silicon, Advisory) on composite engagements
Research and Market Presence
  • Contribute to IOActive’s application security research — vulnerability discovery, novel attack techniques, framework- or platform-specific findings
  • Build personal profile in the application security community: conference talks (Black Hat, DEF CON, OWASP Global, BSides, regional AppSec events), published research, working group participation
  • Represent IOActive in AppSec industry conversations, OSS security efforts, and customer advisory engagements as opportunities arise
What You\'ll Bring
Experience and Background
  • 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review
  • Hands-on engagement delivery across multiple AppSec disciplines — code review, application penetration testing, threat modeling, or SDLC consulting
  • Deep code review expertise in at least two of: JavaScript / TypeScript (Node.js, modern frontends), Python (Django, Flask, FastAPI), Java (Spring, J2EE), C# / .NET (ASP.NET, Core), C / C++, Rust, GoLang. Working competence in additional languages a strong plus.
  • Working knowledge of common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and the security pitfalls particular to each
  • Familiarity with vulnerability classes
  • Nice to have - Familiarity with relevant standards and frameworks: OWASP ASVS, NIST SSDF, BSIMM, SAMM[AM3][AM4]
Capabilities
  • Strong technical credibility and the comfort to operate as the senior voice on engagements
  • Excellent written communication — you produce reports that developers act on rather than file
  • Strong verbal communication, with the ability to both present as a subject matter expert in technical discussions and deliver complex concepts, results, etc. to a general audience
  • Comfort moving between languages and stacks — specialists who insist on a single technology stack don\'t fit this role
  • Collaborative mindset — AppSec engagements typically involve close coordination with delivery teams and client developers
  • Genuine curiosity about how systems work, and patience for reading code carefully — code review consultants who succeed at IOActive are the ones who find the work interesting rather than tedious
Credentials
  • Relevant \"\'bachelor\'s degree or equivalent experience\"
  • Relevant industry certifications strongly preferred: OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security focused credentials
What We Offer

A chance to work with an industry leader in cyber security

Access to world-class technical teams and research

High-energy, collaborative team that values innovation

Flexibility—work remotely or from the office as needed

Competitive compensation and performance-based incentives

  • US base salary range $75,000 - $175,000, depending on experience level, background and location.
Opportunities for travel

If this sounds like your kind of challenge, we’d love to hear from you.

Why I OActive:

We have over 25 years of experience that\'s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space.We\'re one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.

IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.

This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior Security Consultant, Operational Technologies (OT)
Senior Security Consultant, Operational Technologies (OT)

IOActive, Inc. • Brasil

Híbrido
BRL 519 000 - 909 000
Competitive compensation
Flexibility of remote work
Access to world-class technical teams
Senior Security Consultant, Red Team
Senior Security Consultant, Red Team

IOActive, Inc. • Brasil

Híbrido
BRL 380 000 - 761 000
Competitive compensation
Access to technical teams
Flexibility to work remotely
+1
Senior Application Security Engineer - 100% REMOTE
Senior Application Security Engineer - 100% REMOTE

Cibernos • Brasil

Presencial
BRL 180 000 - 300 000
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Brasília

Presencial
BRL 180 000 - 290 000
Growth without limits
Competitive compensation
Flexibility — 100% remote
+3
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Salvador

Teletrabalho
BRL 180 000 - 320 000
Growth without limits
Competitive compensation
Flexibility: 100% remote with flexible
+3
Senior Info Security Analyst
Senior Info Security Analyst

Liferay, Inc. • Recife

Presencial
BRL 180 000 - 260 000
Competitive salary
Open-source culture
Career growth opportunities
+1
Ethical Hacker/Pentester Mid Level (2+ Years) - LATAM
Ethical Hacker/Pentester Mid Level (2+ Years) - LATAM

Insight Assurance • Brasil

Híbrido
BRL 100 000 - 180 000
Principal Consultant, Proactive Services, Unit 42
Principal Consultant, Proactive Services, Unit 42

Palo Alto Networks, Inc. • São Paulo

Híbrido
BRL 200 000 - 300 000
Application Security Engineer
Application Security Engineer

Velozient • Brasil

Teletrabalho
BRL 421 000 - 527 000
15 days PTO
1 floating day
3 sick days
+1
Security Analyst manage DAST, SAST experience 90% english
Security Analyst manage DAST, SAST experience 90% english

Infios • Brasil

Presencial
BRL 120 000 - 240 000