Senior Security Consultant, Application Security
OUR MISSION UNITES US
"Making the world a safer and more secure place. "
It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.
About IOActive :
IOActive , a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.
About the Role
The Senior Consultant, Application Security is a senior technical practitioner in IOActive 's Application Security practice, with secure code review as the central specialty.[AM1][AM2] The role centers on deep manual code audit work across web and systems languages, paired with application penetration testing, threat modeling, and Secure Development Lifecycle (SDLC) advisory engagements.
Code review engagements at IOActive span the full landscape: source code reviews on production codebases for enterprise web applications, mobile backends, embedded systems, and cryptographic implementations; application penetration testing against web, API, and mobile targets; threat modeling for new product designs; and SDLC advisory work helping clients integrate security into their development processes. The Senior Consultant brings particular depth in code review and broad competence across the adjacent work.
What You'll Do
Engagement Delivery — Code Review (primary, ~50–60%)
- Lead manual source code reviews on complex production codebases spanning web applications, mobile backends, APIs, and embedded systems
- Identify vulnerability classes ranging from common (injection, authentication and authorization flaws, SSRF, XSS, deserialization) to nuanced (race conditions, deserialization gadgets, cryptographic implementation flaws, business logic vulnerabilities, architectural weaknesses)
- Author findings reports that developers can act on: clear remediation guidance, working proof-of-concepts where appropriate, and architectural recommendations beyond the immediate fix
- Lead client developer workshops to explain findings and patterns, helping teams build security resilience rather than just fixing the listed issues
Engagement Delivery — Adjacent Application Security Wor
- Application penetration testing across web, API, and mobile targets, particularly where engagements span code review and dynamic testing
- Threat modeling on new product designs and existing systems using STRIDE, attack trees, or equivalent frameworks
- Secure design reviews of architecture, authentication systems, cryptographic implementations, and inter-service communicatio
- SDLC advisory engagements: helping clients integrate code review, threat modeling, and security testing into their development lifecycle (CI/CD, pull-request workflows, developer training)
Client Engagement
- Serve as the senior technical voice in engagement status meetings, client workshops, technical deep-dives, and developer training sessions
- Build trusted technical relationships with client engineering leadership, AppSec teams, and security architects
- Translate technical findings for two distinct audiences: developers who need to fix the issue, and security leadership wh