Remote Opportunity

Senior Security Consultant, Application Security

Join IOActive, Inc. as a senior professional working remotely from United States. Explore the role, benefits, and apply in one place.

Full Time
$75k - $175k
4 weeks ago

IOActive, Inc. is hiring a remote senior full-time Engineering role, Senior Security Consultant, Application Security, for candidates in United States, Spain, United Kingdom. Salary: $75k - $175k. Skills include Secure code review, Threat Modeling, Vulnerability Research, JavaScript.

United States
Spain
United Kingdom
Brazil
Canada
Engineering
Senior
Secure code review
Threat Modeling
Vulnerability Research
+5 more

Job Description

About the Role The Senior Consultant, Application Security is a senior technical practitioner in IOActive's Application Security practice, with secure code review as the central specialty.[AM1] [AM2] The role centers on deep manual code audit work across web and systems languages, paired with application penetration testing, threat modeling, and Secure Development Lifecycle (SDLC) advisory engagements. Code review engagements at

IOActive span the full landscape: source code reviews on production codebases for enterprise web applications, mobile backends, embedded systems, and cryptographic implementations; application penetration testing against web, API, and mobile targets; threat modeling for new product designs; and SDLC advisory work helping clients integrate security into their development processes. The Senior Consultant brings particular depth in code review and broad competence across the adjacent work.

What You'll Do Engagement Delivery — Code Review (primary, ~50–60%) Lead manual source code reviews on complex production codebases spanning web applications, mobile backends, APIs, and embedded systems Identify vulnerability classes ranging from common (injection, authentication and authorization flaws, SSRF, XSS, deserialization) to nuanced (race conditions, deserialization gadgets, cryptographic implementation flaws, business logic vulnerabilities, architectural weaknesses) Author findings reports that developers can act on: clear remediation guidance, working proof-of-concepts where appropriate, and architectural recommendations beyond the immediate fix Lead client developer workshops to explain findings and patterns, helping teams build security resilience rather than just fixing the listed issues Engagement Delivery — Adjacent Application Security Wor Application penetration testing across web, API, and mobile targets, particularly where engagements span code review and dynamic testing Threat modeling on new product designs and existing systems using STRIDE, attack trees, or equivalent frameworks Secure design reviews of architecture, authentication systems, cryptographic implementations, and inter-service communicatio

SDLC advisory engagements: helping clients integrate code review, threat modeling, and security testing into their development lifecycle (CI/CD, pull-request workflows, developer training) Client Engagement Serve as the senior technical voice in engagement status meetings, client workshops, technical deep-dives, and developer training sessions Build trusted technical relationships with client engineering leadership, AppSec teams, and security architects Translate technical findings for two distinct audiences: developers who need to fix the issue, and security leadership who need to understand the business risk and pattern Support pre-sales conversations with technical credibility — scoping calls, capability discussions, and proposal input Practice Contribution and Mentorship Mentor junior and mid-level consultants in code review methodology, vulnerability research, and client engagement — even without direct reporting authority Contribute to IOActive's code review playbooks, tooling, methodologies, and report templates Identify opportunities to extend IOActive's AppSec capability — new tooling, target stacks, research directions, or service offerings Collaborate with adjacent practices (Red Team, Hardware/Silicon, Advisory) on composite engagements Research and Market Presence Contribute to IOActive's application security research — vulnerability discovery, novel attack techniques, framework- or platform-specific findings Build personal profile in the application security community: conference talks (Black Hat, DEF CON, OWASP Global, BSides, regional AppSec events), published research, working group participation Represent IOActive in AppSec industry conversations, OSS security efforts, and customer advisory engagements as opportunities arise

What You'll Bring Experience and Background 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review Hands-on engagement delivery across multiple AppSec disciplines — code review, application penetration testing, threat modeling, or SDLC consulting Deep code review expertise in at least two of: JavaScript / TypeScript (Node.js, modern frontends), Python (Django, Flask, FastAPI), Java (Spring, J2EE), C# / .NET (ASP.NET, Core), C / C++, Rust, GoLang. Working competence in additional languages a strong plus. Working knowledge of common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and the security pitfalls particular to each Familiarity with vulnerability classes Nice to have - Familiarity with relevant standards and frameworks: OWASP ASVS, NIST SSDF, BSIMM, SAMM[AM3] [AM4] Capabilities Strong technical credibility and the comfort to operate as the senior voice on engagements Excellent written communication — you produce reports that developers act on rather than file Strong verbal communication, with the ability to both present as a subject matter expert in technical discussions and deliver complex concepts, results, etc. to a general audience Comfort moving between languages and stacks — specialists who insist on a single technology stack don't fit this role Collaborative mindset — AppSec engagements typically involve close coordination with delivery teams and client developers Genuine curiosity about how systems work, and patience for reading code carefully — code review consultants who succeed at IOActive are the ones who find the work interesting rather than tedious Credentials Relevant bachelor's degree or equivalent experience Relevant industry certifications strongly preferred: OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security focused credentials What We Offer 🎯 A chance to work with an industry leader in cyber security 💡 Access to world-class technical teams and research 🏆 A high-energy, collaborative team that values innovation 💻 Flexibility—work remotely or from the office as needed ✈️ Opportunities for travel 💰 Competitive compensation and performance-based incentives US base salary range $75,000 - $175,000, depending on experience level, background and location. If this sounds like your kind of challenge, we’d love to hear from you. Let’s talk!

Why IOActive

We have over 25 years of experience that’s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space. We're one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter. IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Benefits

  • Remote Work

Skills

Secure code review
Threat Modeling
Vulnerability Research
JavaScript
TypeScript
Python
Application Penetration Testing
SDLC Advisory

Ready to Apply?

Join IOActive, Inc. today

Salary Range
$75k - $175k
Posted 4 weeks ago

More Engineering roles you might like

Discover similar opportunities from companies that are also hiring remotely.

Full Time
3 weeks ago

Sunward Federal Credit Union is hiring a remote mid full-time Engineering role, NV| Mortgage Loan Officer - (Commission with draw), for candidates in United States. Skills include Mortgage Loan Origination, Financial Planning, Credit Analysis, Regulatory Compliance.

United States
Engineering
Backend Engineering
Mid
Mortgage Loan Origination
Financial Planning
Credit Analysis
+5 more
Part Time
$0.015k - $0.02k
3 weeks ago

Modern Mechanical Services is hiring a remote entry part-time Engineering role, After-Hours Dispatcher & Billing/Admin Support, for candidates in United States. Salary: $0.015k - $0.02k. Skills include Dispatching, Billing, Customer Service, Work Order Management.

United States
Engineering
Backend Engineering
Entry
Dispatching
Billing
Customer Service
+5 more
Full Time
3 weeks ago

Canopy Mortgage LLC is hiring a remote senior full-time Engineering role, Mortgage Loan Servicing Manager, for candidates in United States. Skills include Mortgage Servicing, Compliance Auditing, Loan boarding, Financial reporting.

United States
Engineering
Backend Engineering
Senior
Mortgage Servicing
Compliance Auditing
Loan boarding
+5 more

Explore more remote openings

Browse fresh listings from our global community of remote-friendly teams.

Full Time
3 weeks ago

W S DARLEY & CO is hiring a remote mid full-time Sales role, Regional Sales Manager, for candidates in United States. Skills include Sales Prospecting, Government procurement, Customer Relationship Management, Salesforce.

United States
Sales
Account Executive
Mid
Sales Prospecting
Government procurement
Customer Relationship Management
+5 more
Full Time
$73k - $105k
3 weeks ago

HART, INC. is hiring a remote senior full-time Marketing role, Marketing Manager, Communications, for candidates in United States. Salary: $73k - $105k. Skills include Thought Leadership, Blog Writing, Press Releases, Media pitching.

United States
Marketing
Growth Marketing
Senior
Thought Leadership
Blog Writing
Press Releases
+5 more
Full Time
$65k - $68k
3 weeks ago

Thompson Child & Family Focus is hiring a remote mid full-time Human Resources role, HR Generalist, for candidates in United States. Salary: $65k - $68k. Skills include Employee relations, Talent Acquisition, Compliance, full-cycle recruitment.

United States
Human Resources
Mid
Employee relations
Talent Acquisition
Compliance
+5 more
Full Time
3 weeks ago

RS Medical is hiring a remote mid full-time Engineering role, Account Manager, for candidates in United States. Skills include Account Management, Sales Pipeline Building, Salesforce, Interpersonal Communication.

United States
Engineering
Backend Engineering
Mid
Account Management
Sales Pipeline Building
Salesforce
+5 more
Full Time
$140k - $175k
3 weeks ago

MedBridge Inc. is hiring a remote senior full-time Engineering role, Senior Software Engineer, Platform, for candidates in United States. Salary: $140k - $175k. Skills include PHP, CI/CD, MySQL, AWS.

United States
Engineering
Backend Engineering
Senior
PHP
CI/CD
MySQL
+5 more
Full Time
$0.02k - $0.025k
3 weeks ago

ARC Health Partners is hiring a remote entry full-time Design role, Client Acquisition Coordinator, for candidates in United States. Salary: $0.02k - $0.025k. Skills include Inside Sales, B2C Sales, Intake Coordination, Consultative Selling.

United States
Design
Product Design
Entry
Inside Sales
B2C Sales
Intake Coordination
+5 more
Full Time
3 weeks ago

CNB Financial Corporation is hiring a remote mid full-time Engineering role, CNB Bank, nCino Platform Administrator, Remote, for candidates in United States. Skills include Salesforce Administration, Commercial lending, Change Management, Technical Documentation.

United States
Engineering
Backend Engineering
Mid
Salesforce Administration
Commercial lending
Change Management
+5 more
Part Time
3 weeks ago

GoMacro LLC is hiring a remote mid part-time Engineering role, Part-Time Customer Care Specialist, for candidates in United States. Skills include Customer Service, E-Commerce, CRM platforms, Written Communication.

United States
Engineering
Backend Engineering
Mid
Customer Service
E-Commerce
CRM platforms
+5 more
Full Time
3 weeks ago

Grey Street Consulting LLC is hiring a remote senior full-time Operations role, DOT FTA Business Operations Specialist (PRISM), for candidates in United States. Skills include System Administration, User Support, Data Reporting, Training and Onboarding.

United States
Operations
Senior
System Administration
User Support
Data Reporting
+5 more
Full Time
3 weeks ago

CGLRS is hiring a remote entry full-time Product role, Business Development Manager - Entry Level Role, for candidates in Australia. Skills include B2B Sales, Verbal communication, Written Communication, Leadership.

Australia
Product
Product Management
Entry
B2B Sales
Verbal communication
Written Communication
+3 more
Full Time
3 weeks ago

Medical Leverage is hiring a remote entry full-time Engineering role, Project Manager, for candidates in United States. Skills include Project planning, Budget Management, Client Relationship Management, Timeline Development.

United States
Engineering
Backend Engineering
Entry
Project planning
Budget Management
Client Relationship Management
+5 more
Full Time
AUD 140k - AUD 170k
3 weeks ago

Budgetly is hiring a remote senior full-time AI role, AI Platform Engineer (Remote in AU), for candidates in Australia. Salary: AUD 140k - AUD 170k. Skills include TypeScript, React, Agentic Workflows, Systems Thinking.

Australia
AI
Machine Learning
Senior
TypeScript
React
Agentic Workflows
+5 more