Security Consultant - Fixed Term
Boost your chances before you apply.
IOActive, Inc.
US
Summary
The Security Consultant will conduct comprehensive security assessments for web, mobile, and infrastructure environments, including AI-based and traditional penetration testing. They are responsible for identifying vulnerabilities, documenting findings, and providing actionable remediation recommendations to clients.
Job Description
Who you are:
IOActive is looking for Security Consultants who can deliver a range of security assessments including web and mobile application reviews, infrastructure penetration tests, code reviews and security advisory engagements to secure client’s environments and applications. An ideal candidate can is self-motivated and working with internal stakeholders and clients to assess clients products, report findings, and document protocols, policies and procedures.
This position is for a fixed term of up to 3 months with the potential to renew.
What you'll do:
- Conduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems.
- Conduct infrastructure and cloud configuration security reviews
- Conduct assessments incorporating AI-based and traditional pentesting approaches against real world threats.
- Identify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them.
- Prepare clear, professional reports describing identified risks and recommended remediation steps.
- Participate in client meetings and technical discussions
Who you bring:
- 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review
- Hands-on engagement delivery across multiple AppSec disciplines — application penetration testing, code review, or SDLC consulting
- The ability to work independently under deadlines.
- Strong technical credibility and the comfort to operate as a senior voice on engagements
- Excellent written communication — you produce reports that developers act on rather than file
- Strong verbal communication, with the ability to both present as a subject matter expert in technical discussions and deliver complex concepts, results, etc. to a general audience
- Nice to have - Familiarity with relevant standards and frameworks: OWASP, NIST, ISO, SAE
- Relevant bachelor's degree or equivalent experience
- Relevant industry certifications strongly preferred: OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security focused credentials
What We Offer
🎯 A chance to work with an industry leader in cyber security
💡 Access to world-class technical teams and research
🏆 A high-energy, collaborative team that values innovation
💻 Flexibility—work remotely or from the office as needed
✈️ Opportunities for travel
💰 Competitive compensation and benefits with base salaries ranging $65,000 to $150,000 depending on background, experience and location.
If this sounds like your kind of challenge, we’d love to hear from you. Let’s talk!
Why IOActive:
We have over 25 years of experience that’s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space. We're one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.
IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency.
Passion and pride through quality client work is something money simply can't buy. IOActive has spent more than a decade searching for the required blend of characteristics and work ethic that comprise a world-class, international security services team. We are firmly committed to staying on the competitive edge and offering unrelenting value; it's something our customers have come to rely on over the years and can depend on in the future. In fact, IOActive is the only firm in our industry that offers a 100% service satisfaction guarantee.
Boasting a well-rounded and diverse clientele, IOActive works with a majority of Global 500 companies including power and utility, game, hardware, retail, financial, aerospace, healthcare, high-tech, automotive, and software development organizations.
INDUSTRY RECOGNITION
IOActive has won numerous awards throughout the years and was recognized as one of the most important industry companies of the Last 30 Years in SC Media’s 30th Anniversary Awards.
Stay up to date with IOActive and get the latest research insights.
* Facebook: /IOActive
* YouTube: /IOActive
* X: /IOActive
Founded
1998
Company size
51-200 employees
Industry
Computer and Network Security
Org type
Privately Held
Headquarters
Seattle, Washington
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency.
Passion and pride through quality client work is something money simply can't buy. IOActive has spent more than a decade searching for the required blend of characteristics and work ethic that comprise a world-class, international security services team. We are firmly committed to staying on the competitive edge and offering unrelenting value; it's something our customers have come to rely on over the years and can depend on in the future. In fact, IOActive is the only firm in our industry that offers a 100% service satisfaction guarantee.
Boasting a well-rounded and diverse clientele, IOActive works with a majority of Global 500 companies including power and utility, game, hardware, retail, financial, aerospace, healthcare, high-tech, automotive, and software development organizations.
INDUSTRY RECOGNITION
IOActive has won numerous awards throughout the years and was recognized as one of the most important industry companies of the Last 30 Years in SC Media’s 30th Anniversary Awards.
Stay up to date with IOActive and get the latest research insights.
* Facebook: /IOActive
* YouTube: /IOActive
* X: /IOActive
Founded
1998
Company size
51-200 employees
Industry
Computer and Network Security
Org type
Privately Held
Headquarters
Seattle, Washington