Senior Security Consultant, Application Security at Ioactive Tc | Torre

Senior Security Consultant, Application Security

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Freelance
Recurrent
Compensation
USD75k - 175k/year
location_on
Remote (for United States residents)
Remote (for United Kingdom residents)
Remote (for Canada residents)
Remote (for Spain residents)
Shared by
Emma of Torre.ai
13 days ago

Responsibilities


It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.About IOActive:IOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.About the RoleThe Senior Consultant, Application Security is a senior technical practitioner in IOActive's Application Security practice, with secure code review as the central specialty.The role centers on deep manual code audit work across web and systems languages, paired with application penetration testing, threat modeling, and Secure Development Lifecycle (SDLC) advisory engagements.Code review engagements at IOActive span the full landscape: source code reviews on production codebases for enterprise web applications, mobile backends, embedded systems, and cryptographic implementations; application penetration testing against web, API, and mobile targets; threat modeling for new product designs; and SDLC advisory work helping clients integrate security into their development processes. The Senior Consultant brings particular depth in code review and broad competence across the adjacent work.What You'll DoEngagement Delivery — Code Review (primary, ~50–60%)Lead manual source code reviews on complex production codebases spanning web applications, mobile backends, APIs, and embedded systemsIdentify vulnerability classes ranging from common (injection, authentication and authorization flaws, SSRF, XSS, deserialization) to nuanced (race conditions, deserialization gadgets, cryptographic implementation flaws, business logic vulnerabilities, architectural weaknesses)Author findings reports that developers can act on: clear remediation guidance, working proof-of-concepts where appropriate, and architectural recommendations beyond the immediate fixLead client developer workshops to explain findings and patterns, helping teams build security resilience rather than just fixing the listed issuesEngagement Delivery — Adjacent Application Security WorApplication penetration testing across web, API, and mobile targets, particularly where engagements span code review and dynamic testin gThreat modeling on new product designs and existing systems using STRIDE, attack trees, or equivalent frameworksSecure design reviews of architecture, authentication systems, cryptographic implementations, and inter-service communicatio nSDLC advisory engagements: helping clients integrate code review, threat modeling, and security testing into their development lifecycle (CI/CD, pull-request workflows, developer training)Client EngagementServe as the senior technical voice in engagement status meetings, client workshops, technical deep-dives, and developer training sessionsBuild trusted technical relationships with client engineering leadership, AppSec teams, and security architectsTranslate technical findings for two distinct audiences: developers who need to fix the issue, and security leadership who need to understand the business risk and patternSupport pre-sales conversations with technical credibility — scoping calls, capability discussions, and proposal inputPractice Contribution and MentorshipMentor junior and mid-level consultants in code review methodology, vulnerability research, and client engagement — even without direct reporting authorityContribute to IOActive's code review playbooks, tooling, methodologies, and report templatesIdentify opportunities to extend IOActive's AppSec capability — new tooling, target stacks, research directions, or service offeringsCollaborate with adjacent practices (Red Team, Hardware/Silicon, Advisory) on composite engagementsResearch and Market PresenceContribute to IOActive's application security research — vulnerability discovery, novel attack techniques, framework- or platform-specific findingsBuild personal profile in the application security community: conference talks (Black Hat, DEF CON, OWASP Global, BSides, regional AppSec events), published research, working group participationRepresent IOActive in AppSec industry conversations, OSS security efforts, and customer advisory engagements as opportunities ariseWhat You'll BringExperience and Background5+ years in offensive security services, with at least 2–3 years focused on application security and source code reviewHands-on engagement delivery across multiple AppSec disciplines — code review, application penetration testing, threat modeling, or SDLC consultingDeep code review expertise in at least two of: JavaScript / TypeScript (Node.js, modern frontends), Python (Django, Flask, FastAPI), Java (Spring, J2EE), C# / .NET (ASP.NET, Core), C / C++, Rust, GoLang. Working competence in additional languages a strong plus.Working knowledge of common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and the security pitfalls particular to eachFamiliarity with vulnerability classesNice to have - Familiarity with relevant standards and frameworks: OWASP ASVS, NIST SSDF, BSIMM, SAMMCapabilitiesStrong technical credibility and the comfort to operate as the senior voice on engagementsExcellent written communication — you produce reports that developers act on rather than fileStrong verbal communication, with the ability to both present as a subject matter expert in technical discussions and deliver complex concepts, results, etc. to a general audienceComfort moving between languages and stacks — specialists who insist on a single technology stack don't fit this roleCollaborative mindset — AppSec engagements typically involve close coordination with delivery teams and client developersGenuine curiosity about how systems work, and patience for reading code carefully — code review consultants who succeed at IOActive are the ones who find the work interesting rather than tediousCredentialsRelevant bachelor's degree or equivalent experienceRelevant industry certifications strongly preferred: OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security focused credentialsWhat We Offer🎯 A chance to work with an industry leader in cyber security💡 Access to world-class technical teams and research🏆 A high-energy, collaborative team that values innovation💻 Flexibility—work remotely or from the office as needed✈️ Opportunities for travel💰 Competitive compensation and performance-based incentivesUS base salary range $75,000 - $175,000, depending on experience level, background and location.If this sounds like your kind of challenge, we’d love to hear from you. Let’s talk!Why IOActive:We have over 25 years of experience that’s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space.We're one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.