\"Making the world a safer and more secure place.\" \"
It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.
About IOActive:
IOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.
Who you are:
The Managing Consultant (MC) is a hybrid role within IOActive’s Services organization, formalized to make more efficient use of IOActive’s resources and better serve our clients. The MC has part of the responsibilities traditionally held by Directors, Project Managers, and Security Consultants — without changing the underlying accountability model: the assigned Director remains responsible for project delivery, Security Consultants remain responsible for technical execution, and the Project Manager (where assigned) remains responsible for managing the project.
MCs play a critical role across technical knowledge management, sales support, project management, hands-on consulting, and team management, and act as a force multiplier for Directors driving business growth. The role serves two primary purposes: leading technical conversations with clients during the planning phase to ensure engagements are properly scoped and assisting Directors and Business Development Managers (BDMs) during the sales process to help design feasible, accurate proposals. MCs may also serve as a line manager for assigned Security Consultants.
This is an earlier-career-stage counterpart to the Director of Services role: the MC applies the same client‑facing judgment, technical credibility, and delivery oversight, at a scope suited to a consultant building toward people leadership rather than a fully management‑focused position.
What you'll do:
Sales Support and Technical Scoping
- Lead technical scoping and requirements‑gathering conversations with clients during the planning phase, ensuring proposals reflect client needs and consultants receive the technical detail required for execution.
- Facilitate the Project Profitability Model (PPM) process to establish clear project objectives, technical requirements, and level of effort.
- Assist in drafting sections of Statements of Work (SoW), including scope of services, deliverables, and respective responsibilities.
- Participate in client discussions and meetings alongside the BDM to help build a tailored, well‑scoped proposal.
Technical Project Leadership and Delivery
- Coordinate with the Project Manager to establish an action plan enumerating project tasks and ownership; assume technical coordination while logistics remain with the PM.
- Execute or oversee technical project‑management tasks, including access requests, credentials management, asset deployment, and sensor whitelisting.
- Proactively identify and troubleshoot technical issues that arise during project execution, such as device malfunctions, access restrictions, etc.
- Serve as a client point of contact for escalating critical or urgent findings and coordinating required testing notifications.
- In the absence of an assigned Project Manager, assume PM duties to ensure timely delivery, including client follow‑up, timesheet review, and project close‑out.
- Provide technical review and approval of reports prior to client delivery, in partnership with the assigned Director.
Consulting and Subject Matter Expertise
- Serve as a subject matter expert on specific projects, clients, or technical fields where background and expertise warrant direct involvement.
- Lead the delivery of final reports, synthesizing complex technical findings into clear, actionable recommendations for clients.
- Collaborate with cross‑functional teams to develop innovative solutions and drive continuous improvement in service delivery.
- Maintain billable utilization at or below 25% when staffed as a regular consultant, preserving capacity for scoping, sales support, and team‑management duties.
Team Leadership and Development
- Serve as line manager for assigned Security Consultants, including leading weekly check‑ins and monthly one‑on‑one meetings.
- Mentor and guide consultants to support their professional development and job satisfaction.
- Proactively address challenges or concerns raised by consultants, providing support and guidance.
- Solicit consultant feedback on project experiences to inform annual performance reviews.
Director Support and Business Growth
- Strengthen client relationships and contribute to business growth by enforcing best practices, ensuring exceptional service delivery, and identifying opportunities for client expansion.
- Act as the main point of contact for assigned clients, with the Director available as an escalation contact.
- Collaborate with Directors on strategic initiatives and projects that support broader business objectives.
- Help Directors stay focused on strategy and growth by absorbing day‑to‑day scoping, delivery‑support, and consultant‑management responsibilities.
What you bring:
Experience and Background
- 4+ years in offensive security services, with substantial hands‑on delivery experience across client engagements.
- Prior experience leading technical scoping, project coordination, or informal team leadership; formal people‑management experience is a plus but not required.
- Strong technical background in at least one offensive security service line (application security, red team, mobile security, security architecture, IC/S OT/SCADA, SDL, or related disciplines), with working familiarity across others.
- Demonstrated ability to translate technical findings into client‑ready recommendations and to support proposal and SoW development.
- Experience supporting or participating in the sales process, including scoping calls and level‑of‑effort estimation, preferred.