Associate Security Consultant

IOActive, Inc.

United States

Hybrid

USD 46,000 - 58,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote work flexibility
Travel opportunities
Competitive compensation

Job summary

IOActive, Inc. is seeking an Associate Security Consultant to deliver application and infrastructure security services across industries. You will participate in security assessments, web and mobile reviews, and infrastructure penetration tests while growing technical consulting skills.

You'll work with experienced consultants, develop reports with actionable remediation guidance, and collaborate with client teams to align security with business goals. Remote work flexibility is available.

Qualifications

  • 1-3 years of experience in offensive security services focusing on web, mobile, and infrastructure testing.
  • Knowledge of OWASP Top 10 vulnerabilities.
  • Experience with Burp Suite, OWASP ZAP, or Nessus.
  • Proficiency with Windows and GNU/Linux OS concepts.
  • Basic scripting or programming experience (Python, JavaScript, Bash, PowerShell).

Responsibilities

  • Conduct security assessments for web and mobile apps, APIs, and infrastructure.
  • Perform penetration testing using manual techniques and tools.
  • Document vulnerabilities with actionable remediation steps.
  • Assist in client engagements and report findings clearly.

Skills

Offensive security
Penetration testing
Web security
Mobile security
Network concepts

Education

Bachelor's degree in Computer Science or related field

Tools

Burp Suite
OWASP ZAP
Tenable Nessus

Job description

Who you are

The Associate Security Consultant delivers application and infrastructure security services for clients across a variety of industries. Working alongside experienced consultants, this role actively participates in security assessments, web and mobile application reviews, infrastructure penetration tests, and security advisory engagements while developing technical consulting skills.

This is an excellent opportunity for someone with a strong interest in cybersecurity who enjoys problem solving, learning new technologies, and working with industry experts to improve software security.

What You’ll Do
Security Assessments
  • Conduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems.
  • Conduct infrastructure security reviews
  • Where suitable, deliver the above activities with support from more experienced consultants.
  • Carry out penetration testing activities using both manual techniques and industry-standard security tools.
  • Identify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them.
  • Verify and validate remediation actions to confirm fixes applied work as intended.
Client Engagement
  • Contribute to client engagements by verifying testing prerequisites are met, collecting information, performing technical testing, and documenting findings.
  • Prepare clear, professional reports describing identified risks and recommended remediation steps.
  • Participate in client meetings and technical discussions alongside senior consultants.
  • Develop an understanding of client environments, technologies, and business objectives.
Collaboration
  • Work closely with other consultants on project delivery.
  • Collaborate with software developers, security teams, and project stakeholders from clients across multiple industries.
  • Share knowledge and contribute to internal documentation and best practices.
  • Participate in internal technical trainings.
Professional Development
  • Continuously build knowledge of security concepts, tools, and emerging threats.
  • Participate in internal research, lab exercises, and knowledge-sharing sessions.
  • Stay current with security trends, vulnerabilities, and secure development practices.
  • Support continuous improvement of assessment methodologies and documentation.
What You’ll Bring
  • 1-3 years of experience in offensive security services doing web, mobile and infrastructure penetration tests and vulnerability assessments.
  • Good knowledge of common web, mobile, and infrastructure vulnerabilities as those described in OWASP Top 10 respective projects.
  • Experience with security tools such as Burp Suite, OWASP ZAP, or Tenable Nessus.
  • Understanding of operating systems concepts including Windows and GNU/Linux.
  • Basic experience with scripting or programming languages (e.g. Python, Javascript, Bash, PowerShell, C/C++).
  • Knowledge of networking concepts and protocols.
  • Familiarity with security testing methodologies.
  • Experience with cloud security best practices (AWS, Azure, Google) is valued but not required.
  • Internship, academic, Capture the Flag (CTF), open-source, or personal project experience in cybersecurity is valued but not required.
  • Knowledge of secure software development practices is valued but not required.
  • Strong analytical and problem-solving abilities.
  • Curiosity and enthusiasm for learning new technologies.
  • Good written and verbal English communication skills.
  • Ability to explain technical concepts clearly.
  • Strong attention to detail.
  • Ability to work independently while collaborating effectively within a team.
  • Professionalism when interacting with clients and colleagues.
  • Strong organizational and time management skills.
  • Bachelor’s degree in computer science, Information Security, Information Technology, Software Engineering, or a related discipline, or equivalent practical experience.
  • Relevant certifications such as OSCP, OSWE, BSCP or similar offensive security trainings are a strong plus.
  • A willingness to pursue additional professional certifications and ongoing technical development.
What We Offer

A chance to work with an industry leader in cyber security

Access to world-class technical teams and research

A high-energy, collaborative team that values innovation

Flexibility—work remotely or from the office as needed

Opportunities for travel

Competitive compensation range targeted €40,000 - €50,000

IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.

This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Consultant - Fixed Term
Security Consultant - Fixed Term

Socket.dev • United States

Hybrid
USD 65,000 - 150,000
Security Consultant - Fixed Term
Security Consultant - Fixed Term

Fleet Glass Services, Inc. • Northern (KY)

Hybrid
USD 65,000 - 150,000
Remote work option
Travel opportunities
Competitive compensation
Senior Security Consultant, Red Team
Senior Security Consultant, Red Team

IOActive, Inc. • United States

Hybrid
USD 75,000 - 150,000
Competitive compensation
Access to world-class technical teams
Flexibility to work remotely or from the office
+1
Senior Embedded Security Consultant - US
Senior Embedded Security Consultant - US

IOActive, Inc. • Seattle (WA)

Hybrid
USD 90,000 - 175,000
PTO
Medical, Dental, Vision Insurance
401(k) match
+2
Senior Security Consultant, Operational Technologies (OT)
Senior Security Consultant, Operational Technologies (OT)

IOActive, Inc. • Seattle (WA)

Hybrid
GBP 100,000 - 175,000
Flexibility to work remotely or from the office
Opportunities for travel
Competitive compensation
+1
Managing Consultant
Managing Consultant

United States Digital Space LLC • United States

Hybrid
USD 100,000 - 185,000
Remote or office flexibility
World-class technical teams
Managing Consultant
Managing Consultant

IOActive, Inc. • Northern (KY)

Hybrid
USD 100,000 - 185,000
Remote work flexibility
Travel opportunities
Competitive compensation
Director of Services - US West
Director of Services - US West

IOActive, Inc. • United States

Hybrid
USD 150,000 - 200,000
Bonus potential
Remote work flexibility
Travel opportunities
Offensive Security Consultant
Offensive Security Consultant

Konica Minolta Business Solutions Canada • Kansas City (MO)

On-site
USD 80,000 - 100,000
AI Security Consultant
AI Security Consultant

IOActive, Inc. • Seattle (WA)

Hybrid
USD 75,000 - 175,000
Work with industry leader in cyber sec
Access to world-class technical teams
High-energy collaborative team
+3