Full-Time

Application Security Consultant

Application Security

Updated on 9/16/2026

IOActive

IOActive

51-200 employees

Penetration testing and attacker-perspective security

Compensation Overview

$75k - $175k/yr

+ Performance-based incentives

Remote in USA + 3 more

More locations: Canada | Spain | United Kingdom

Hybrid

Remote work is available from the United States; the role may also be worked from an office as needed and includes opportunities for travel.

Bachelor's

Category
Cybersecurity (1)
Required Skills
Rust
FastAPI
Python
JavaScript
Node.js
ASP.NET
Threat modeling
Java
ISC2 CSSLP
TypeScript
.NET
C#
Go
Cryptography
Flask
C/C++
DevOps
Spring
Django

Get referred to IOActive

See people who can refer or advise you

Requirements
  • At least 5 years of experience in offensive security services, including 2–3 years focused on application security and source code review.
  • Hands-on engagement delivery across code review, application penetration testing, threat modeling, or Secure Development Lifecycle consulting.
  • Deep code review expertise in at least two of JavaScript or TypeScript, Python, Java, C# or .NET, C or C++, Rust, and Go.
  • Working knowledge of common framework patterns, object-relational mapping behavior, authentication and authorization libraries, cryptographic libraries, and security pitfalls associated with each.
  • Familiarity with vulnerability classes.
  • A relevant bachelor's degree or equivalent experience.
Responsibilities
  • Lead manual source code reviews on complex production codebases spanning web applications, mobile backends, application programming interfaces, and embedded systems.
  • Identify common and nuanced vulnerability classes, including injection, authentication and authorization flaws, server-side request forgery, cross-site scripting, deserialization, race conditions, deserialization gadgets, cryptographic implementation flaws, business logic vulnerabilities, and architectural weaknesses.
  • Author findings reports with remediation guidance, working proof-of-concepts where appropriate, and architectural recommendations.
  • Lead client developer workshops explaining findings and patterns.
  • Perform application penetration testing across web, application programming interface, and mobile targets.
  • Conduct threat modeling for new product designs and existing systems using STRIDE, attack trees, or equivalent frameworks.
  • Perform secure design reviews of architecture, authentication systems, cryptographic implementations, and inter-service communication.
  • Advise clients on integrating code review, threat modeling, and security testing into their development lifecycle, including continuous integration and continuous delivery, pull-request workflows, and developer training.
  • Serve as the senior technical voice in engagement status meetings, client workshops, technical deep-dives, and developer training sessions.
  • Build technical relationships with client engineering leadership, application security teams, and security architects.
  • Translate technical findings for developers and security leadership.
  • Support pre-sales conversations through scoping calls, capability discussions, and proposal input.
  • Mentor junior and mid-level consultants in code review methodology, vulnerability research, and client engagement without direct reporting authority.
  • Contribute to code review playbooks, tooling, methodologies, and report templates.
  • Identify opportunities to extend application security capabilities through tooling, target stacks, research directions, or service offerings.
  • Collaborate with Red Team, Hardware/Silicon, and Advisory practices on composite engagements.
  • Contribute to application security research, including vulnerability discovery, novel attack techniques, and framework- or platform-specific findings.
  • Represent the company in application security industry conversations, open-source security efforts, and customer advisory engagements.
Desired Qualifications
  • Familiarity with OWASP Application Security Verification Standard, National Institute of Standards and Technology Secure Software Development Framework, Building Security In Maturity Model, or Software Assurance Maturity Model.
  • Relevant industry certifications such as OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security-focused credentials.
  • Working competence in additional programming languages beyond the primary languages.
  • Experience presenting at Black Hat, DEF CON, OWASP Global, BSides, or regional application security events; publishing research; or participating in working groups.

IOActive provides security services to large enterprises across industries. It uses research-driven methods to perform deep security work such as full-stack penetration testing, program efficacy assessments, and hardware hacking, bringing an attacker’s perspective to help clients strengthen their security posture and business resiliency. Its offerings are delivered as specialized technical and programmatic services aimed at maximizing the value of security investments. The company differentiates itself with its 100% service satisfaction guarantee, a long track record, and recognition in the security industry, serving many Global 500 organizations including power, retail, financial, healthcare, and technology sectors. The overall goal is to help clients reduce risk and improve resilience through hands-on testing, audits, and strategic security assessments.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Seattle, Washington

Founded

1998

Get referred to IOActive

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • April 2026 AI-generated-code research created fresh visibility across DevOps and security teams.
  • August 2026 water-utility and PLC coverage keeps IOActive aligned with urgent OT demand.
  • Recent media placements and speaking hits strengthen recruiting for consultants and researchers.

What critics are saying

  • No funding or acquisition disclosure suggests limited scale against larger consultancies and product vendors.
  • IOActive depends on billable research relevance; stale findings quickly commoditize its employer brand.
  • A failed large-enterprise pivot risks slow hiring and margin pressure by 2027.

What makes IOActive unique

  • IOActive still publishes high-signal OT and embedded research, including April 2026 AI-code analysis.
  • Its whitepapers target hard-to-test niches like SATCOM, PLCs, and industrial ransomware.
  • Founder Joshua Pennell remains chairman, signaling continuity around technical credibility and brand.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company News

GlobeNewswire
May 15th, 2024
Ioactive Recognized For Trailblazing Cybersecurity Practices At 2024 Global Infosec Awards

SEATTLE, May 15, 2024 (GLOBE NEWSWIRE) -- IOActive, Inc., the worldwide leader in research-fueled security services, was named as a winner of the Trailblazing Cybersecurity Research and Trailblazing Cybersecurity Provider categories by Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. “This selection from Cyber Defense Magazine as one of the industry’s most influential cybersecurity research firms is a testament to the hard work and expertise of our team,” said Jennifer Sunshine Steffens, CEO at IOActive. “We believe in approaching cybersecurity from an attackers’ perspective, and this philosophy underpins everything we do - from our groundbreaking research across industries to our comprehensive security services tailored to meet the evolving needs of our clients. As we continue to innovate and push the boundaries of cybersecurity, we remain steadfast in our mission to make the world a safer place for all.” This award highlights ongoing momentum for the company as Steffens was recently recognized as one of The Top 50 Women Leaders of Washington for 2024, in addition to IOActive winning three award categories at the 2024 Cybersecurity Excellence Awards. IOActive is proud to be recognized as part of a coveted group of industry leaders. The full list of this year’s award recipients can be found here: http://www.cyberdefenseawards.com/ For more information, please visit www.ioactive.com or join us on LinkedIn and X

FreightWaves
Jun 5th, 2023
Is Your System Vulnerable To Cyberattacks? Here’S How To Find Out

“What should keep you up at night is, ‘What do I not know?’ There may be things that you know you don’t know, and there may be things you don’t know that you don’t know.”During the National Motor Freight Traffic Association’s (NMFTA) May webinar, John Sheehy, senior vice president of research and strategy at IOActive, a research-fueled security services firm, offered that thought-provoking reminder.Sheehy’s presentation, hosted by Antwan Banks, director of cybersecurity of NMFTA, is part of the organization’s cybersecurity series leading up to its October Digital Solutions Conference in Houston. The conference will be a meeting of minds to discuss emerging cybersecurity threats and related issues faced by the transportation and logistics industries.Cybercrime attacks on large transportation businesses have made headlines in recent years, and as the industry has become more appealing to attackers, companies of all sizes are vulnerable to system breaches. The range of threat techniques only continues to grow as hackers adapt and evolve ways to gain access to critical company information.For transportation companies, threats don’t just apply to internal digital systems, but also to the vehicles and equipment they use to move freight. Additionally, how these systems interface with one another through telematics devices presents risk. With many entry points for hackers, the importance of cybersecurity is paramount.The prevalence of these “hackable” interfaces that organizations build their business on provides malicious individuals and entities many opportunities to breach an organization and wreak havoc.“[It] could be as simple as one of your employee’s laptops or something more complex such as your overall wide area network. Or … from an operational technology perspective, something that might move freight on the warehouse floor that is necessary for shipping and receiving can be disrupted too,” Sheehy elaborated.Identifying critical digital security lapses is the first step in defending your business from bad actors, who, in the worst-case scenario, could pose an existential threat to your company.Penetration testing is one of the most impactful ways to figure out what it is you don’t know about your company’s vulnerabilities, allowing you to mitigate risks before an attacker can exploit them.During the webinar, Sheehy discussed what penetration tests are, as well as the methodologies and the best practices you can implement to gain maximum value from them.What is a penetration test?Simulating an attack on your computer system or network using the same tools, techniques and procedures as the real thing, penetration testing allows an organization to evaluate its security and expose the business impacts of its vulnerabilities. “These vulnerabilities may result from poor or improper system configuration, known and/or unknown hardware or software flaws, or operational weaknesses in processes or technical countermeasures,” Banks said.Penetration test methodologiesPenetration tests are not one-size-fits-all processes; Sheehy identified three main kinds of test methodologies, which fall on a spectrum from limited to more information provided to testers