安全顾问 - 固定期限
Security Consultant - Fixed Term
我们致力于让世界变得更安全、更可靠
这是我们简单而明确的使命。它驱动着我们所做的每一件事——从研究到客户工作再到社区参与。它将我们的全球团队凝聚成一支具有诚信、炽热激情和不懈创造力的精英队伍,我们不只是“突破界限”或“跳出框框思考”,而是彻底撕碎信封、碾碎盒子,并且乐在其中。我们一直在寻找与我们使命一致的人加入我们。
关于IOActive:
IOActive是全球1000强企业的值得信赖的合作伙伴,为所有行业提供以研究驱动的安全服务。我们的前沿网络安全团队提供高度专业化的技术和程序化服务,包括全栈渗透测试、项目有效性评估和硬件破解。IOActive在每个项目中都带来独特的攻击者视角,以最大化网络安全投资并提升客户的网络安全态势和运营弹性。IOActive成立于1998年,总部位于西雅图,拥有全球业务,包括位于华盛顿州西雅图、西班牙马德里和英国切尔滕纳姆的先进硬件破解实验室。
你是什么样的人:
IOActive正在寻找能够开展一系列安全评估的网络安全顾问,包括网页和移动应用审查、基础设施渗透测试、代码审查和安全咨询项目,以保护客户的环境和应用。理想的候选人具备自我驱动力,能与内部利益相关者和客户合作,评估客户产品,报告发现的问题,并记录协议、政策和流程。
该职位为最多3个月的固定期限,有续签可能。
你会做什么:
- 对网页和移动应用(Android/iOS)、API和其他软件系统进行应用安全评估。
- 进行基础设施和云配置安全审查。
- 结合基于AI的传统渗透测试方法,针对现实世界威胁进行评估。
- 识别并记录安全漏洞、配置错误和最佳实践偏差,提供可操作的改进建议。
- 准备清晰、专业的报告,描述已识别的风险和推荐的修复步骤。
- 参与客户会议和技术讨论。
你带来的:
- 在进攻性安全服务领域有5年以上经验,其中至少2-3年专注于应用安全
查看英文原文
OUR MISSION UNITES US
"Making the world a safer and more secure place."
It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.
About IOActive:
IOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.
Who you are:
IOActive is looking for Security Consultants who can deliver a range of security assessments including web and mobile application reviews, infrastructure penetration tests, code reviews and security advisory engagements to secure client’s environments and applications. An ideal candidate can is self-motivated and working with internal stakeholders and clients to assess clients products, report findings, and document protocols, policies and procedures.
This position is for a fixed term of up to 3 months with the potential to renew.
What you'll do:
- Conduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems.
- Conduct infrastructure and cloud configuration security reviews
- Conduct assessments incorporating AI-based and traditional pentesting approaches against real world threats.
- Identify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them.
- Prepare clear, professional reports describing identified risks and recommended remediation steps.
- Participate in client meetings and technical discussions
Who you bring:
- 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review
- Hands-on engagement delivery across multiple AppSec disciplines — application penetration testing, code review, or SDLC consulting
- The ability to work independently under deadlines.
- Strong technical credibility and the comfort to operate as a senior voice on engagements
- Excellent written communication — you produce reports that developers act on rather than file
- Strong verbal communication, with the ability to both present as a subject matter expert in technical discussions and deliver complex concepts, results, etc. to a general audience
- Nice to have - Familiarity with relevant standards and frameworks: OWASP, NIST, ISO, SAE
- Relevant bachelor's degree or equivalent experience
- Relevant industry certifications strongly preferred: OSCP, OSWE, GWAPT, CSSLP, GWEB, or equivalent application-security focused credentials
What We Offer
🎯 A chance to work with an industry leader in cyber security
💡 Access to world-class technical teams and research
🏆 A high-energy, collaborative team that values innovation
💻 Flexibility—work remotely or from the office as needed
✈️ Opportunities for travel
💰 Competitive compensation and benefits with base salaries ranging $65,000 to $150,000 depending on background, experience and location.
If this sounds like your kind of challenge, we’d love to hear from you. Let’s talk!
WhyIOActive:
We have over 25 years of experience that’s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space. We're one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.
IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.
Originally posted on Himalayas