Associate Security Consultant

IOActive, Inc.

Deutschland

Hybrid

EUR 40.000 - 50.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Remote work
Travel opportunities
Competitive compensation

Zusammenfassung

IOActive, Inc. is seeking an Associate Security Consultant to deliver application and infrastructure security services across industries. You will work with seasoned consultants on security assessments, web/mobile reviews, and advisory engagements while building technical consulting skills.

This role offers flexibility to work remotely or from the office as needed, with opportunities to travel and engage with clients globally. A strong interest in cybersecurity and problem solving is essential.

Qualifikationen

  • 1-3 years in offensive security performing web, mobile and infrastructure testing.
  • Knowledge of OWASP Top 10 and related vulnerabilities.
  • Experience with Burp Suite, OWASP ZAP, or Nessus.
  • Bachelor’s degree in CS/InfoSec or equivalent practical experience; OSCP a plus.

Aufgaben

  • Conduct web and mobile application security assessments.
  • Perform infrastructure security reviews and penetration tests.
  • Document findings and provide actionable remediation recommendations.
  • Collaborate with clients and senior consultants during engagements.
  • Verify remediation actions and confirm fixes.

Kenntnisse

Penetration testing
Security assessments
English communication

Ausbildung

Bachelor’s degree in Computer Science or related
OSCP or similar offensive security cert

Tools

Burp Suite
OWASP ZAP
Tenable Nessus

Jobbeschreibung

Who you are

The Associate Security Consultant delivers application and infrastructure security services for clients across a variety of industries. Working alongside experienced consultants, this role actively participates in security assessments, web and mobile application reviews, infrastructure penetration tests, and security advisory engagements while developing technical consulting skills.

This is an excellent opportunity for someone with a strong interest in cybersecurity who enjoys problem solving, learning new technologies, and working with industry experts to improve software security.

What You’ll Do
Security Assessments
  • Conduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems.
  • Conduct infrastructure security reviews
  • Where suitable, deliver the above activities with support from more experienced consultants.
  • Carry out penetration testing activities using both manual techniques and industry-standard security tools.
  • Identify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them.
  • Verify and validate remediation actions to confirm fixes applied work as intended.
Client Engagement
  • Contribute to client engagements by verifying testing prerequisites are met, collecting information, performing technical testing, and documenting findings.
  • Prepare clear, professional reports describing identified risks and recommended remediation steps.
  • Participate in client meetings and technical discussions alongside senior consultants.
  • Develop an understanding of client environments, technologies, and business objectives.
Collaboration
  • Work closely with other consultants on project delivery.
  • Collaborate with software developers, security teams, and project stakeholders from clients across multiple industries.
  • Share knowledge and contribute to internal documentation and best practices.
  • Participate in internal technical trainings.
Professional Development
  • Continuously build knowledge of security concepts, tools, and emerging threats.
  • Participate in internal research, lab exercises, and knowledge-sharing sessions.
  • Stay current with security trends, vulnerabilities, and secure development practices.
  • Support continuous improvement of assessment methodologies and documentation.
What You’ll Bring
  • 1-3 years of experience in offensive security services doing web, mobile and infrastructure penetration tests and vulnerability assessments.
  • Good knowledge of common web, mobile, and infrastructure vulnerabilities as those described in OWASP Top 10 respective projects.
  • Experience with security tools such as Burp Suite, OWASP ZAP, or Tenable Nessus.
  • Understanding of operating systems concepts including Windows and GNU/Linux.
  • Basic experience with scripting or programming languages (e.g. Python, Javascript, Bash, PowerShell, C/C++).
  • Knowledge of networking concepts and protocols.
  • Familiarity with security testing methodologies.
  • Experience with cloud security best practices (AWS, Azure, Google) is valued but not required.
  • Internship, academic, Capture the Flag (CTF), open-source, or personal project experience in cybersecurity is valued but not required.
  • Knowledge of secure software development practices is valued but not required.
  • Strong analytical and problem-solving abilities.
  • Curiosity and enthusiasm for learning new technologies.
  • Good written and verbal English communication skills.
  • Ability to explain technical concepts clearly.
  • Strong attention to detail.
  • Ability to work independently while collaborating effectively within a team.
  • Professionalism when interacting with clients and colleagues.
  • Strong organizational and time management skills.
  • Bachelor’s degree in computer science, Information Security, Information Technology, Software Engineering, or a related discipline, or equivalent practical experience.
  • Relevant certifications such as OSCP, OSWE, BSCP or similar offensive security trainings are a strong plus.
  • A willingness to pursue additional professional certifications and ongoing technical development.
What We Offer
  • A chance to work with an industry leader in cyber security
  • Access to world-class technical teams and research
  • A high-energy, collaborative team that values innovation
  • Flexibility—work remotely or from the office as needed
  • Opportunities for travel
  • Competitive compensation range targeted €40,000 - €50,000

If this sounds like your kind of challenge, we’d love to hear from you.

Why IOActive

We have over 25 years of experience that’s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for ourinnovation and thought leadership within our high-profile, cutting edge space. We’re one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.

IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.

This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Security Consultant, Application Security
Senior Security Consultant, Application Security

IOActive, Inc. • Deutschland

Hybrid
EUR 70.000 - 150.000
Remote work flexibility
Travel opportunities
Competitive compensation
Embedded Device Security Consultant
Embedded Device Security Consultant

Embedded Shishya • Deutschland

Hybrid
EUR 69.000 - 103.000
PTO
Holiday
Medical
+7
Sales Development Representative - US
Sales Development Representative - US

Embedded Shishya • Deutschland

Remote
EUR 39.000 - 56.000
Remote work option
Travel opportunities
Competitive pay
Cyber Security Consultant - Penetration Testing
Cyber Security Consultant - Penetration Testing

Bitdefender • Deutschland

Vor Ort
EUR 90.000 - 130.000
Annual training budget
Dedicated research time
Global collaboration
Senior Security Engineer
Senior Security Engineer

United States Digital Space LLC • Berlin, München

Vor Ort
EUR 90.000 - 125.000
Relocation support
Learning allowance
Health & wellness
+3
Specialist - Information Security
Specialist - Information Security

Everise • Deutschland

Hybrid
EUR 65.000 - 95.000
Cyber Security Pentester (m/f/d)
Cyber Security Pentester (m/f/d)

ECSO • Mülheim an der Ruhr

Vor Ort
EUR 45.000 - 65.000
Security Engineer (m/f/d)
Security Engineer (m/f/d)

Security Research Labs • Berlin

Hybrid
EUR 55.000 - 90.000
Gym discounts
Public transport pass
German lessons
+5
Information Security Analyst
Information Security Analyst

Impala Search • Berlin

Hybrid
USD 64.000 - 100.000
Senior Product Manager - CISO Advantage (m/f/d)
Senior Product Manager - CISO Advantage (m/f/d)

Sophos • Deutschland

Vor Ort
USD 75.000 - 95.000
Remote-first working model
Diversity and inclusion initiatives
Global wellbeing days