Security Consultant - Fixed Term
OUR MISSION UNITES US
"Making the world a safer and more secure place. "
It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.
About IOActive :
IOActive , a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.
Who you are :
IOActive is looking for Security Consultants who can deliver a range of security assessments including web and mobile application reviews, infrastructure penetration tests, code reviews and security advisory engagements to secure client’s environments and applications. An ideal candidate can is self-motivated and working with internal stakeholders and clients to assess clients products, report findings, and document protocols, policies and procedures.
This position is for a fixed term of up to 3 months with the potential to renew.
What you'll do:
- Conduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems.
- Conduct infrastructure and cloud configuration security reviews
- Conduct assessments incorporating AI-based and traditional pentesting approaches against real world threats.
- Identify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them.
- Prepare clear, professional reports describing identified risks and recommended remediation steps.
- Participate in client meetings and technical discussions
Who you bring:
- 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review
- Hands-on engagement delivery across multiple AppSec disciplines — application penetration testing, code review, or SDLC consulting
- The ability to work independently under deadlines.
- Strong technical credibility and the comfort to operate as a senior voice on engagements
- Excellent written communication — you produce reports that developers act on rather than file
- Strong verbal communication, with the ability to both present as a subject matter expert in technical discussions and deliver complex concepts, results, etc. to a general audience
- Nice to have - Familiarity with relevant standards and frameworks: OWASP, NIST, ISO, SAE
- Relevant bachelor's degree or equivalent experience
- Relevant industry certifications strongly preferred: OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security focused credentials
What We Offer
🎯 A chance to work with an industry leader in cyber security
💡 Access to world-class technical teams and research
🏆 A high-energy, collaborative team that values innovation
💻 Flexibility—work remotely or from the office as needed
✈️ Opportunities for travel
💰 Competitive compensation and benefits with base salaries ranging $65,000 to $150,000 depending on background, experience and location.
If this sounds like your kind of challenge, we’d love to hear from you. Let’s talk!
Why I O Active:
We have over 25 years of experience that’s established and stable; yet high-growt
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels →Get remote jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks — continue to the application ↗