Senior Security Consultant, Application Security

I
IOActiveCybersecurity consulting
BrazilFull-TimeSenior
SalaryUS base salary range $75,000 - $175,000, depending on experience level, background and location.
Apply NowOpens the employer's application page

Job Details

Experience
5+ years in offensive security services, with at least 2–3 years focused on application security and source code review
Required Skills
PythonJavaJavascriptTypeScript

Requirements

  • Have 5+ years of experience in offensive security services, including at least 2–3 years focused on application security and source code review.
  • Bring hands-on engagement delivery experience across code review, application penetration testing, threat modeling, or SDLC consulting.
  • Have deep code review expertise in at least two of JavaScript/TypeScript, Python, Java, C#/.NET, C/C++, Rust, or Go.
  • Understand common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and their security pitfalls.
  • Have a relevant bachelor's degree or equivalent experience.
  • Relevant industry certifications are strongly preferred, such as OSCP, OSWE, GWAPT, CSSLP, or GWEB.
  • Familiarity with OWASP ASVS, NIST SSDF, BSIMM, or SAMM is a plus.
  • Be able to produce clear written reports and present technical findings to developer and general audiences.
  • Be comfortable working across languages and technology stacks and collaborating with delivery teams and client developers.

Responsibilities

  • Lead manual source code reviews on complex production codebases across web applications, mobile backends, APIs, and embedded systems.
  • Identify common and nuanced vulnerabilities, and write findings reports with remediation guidance, proof-of-concepts where appropriate, and architectural recommendations.
  • Lead developer workshops to explain findings and security patterns.
  • Perform application penetration testing across web, API, and mobile targets.
  • Conduct threat modeling and secure design reviews of architectures, authentication systems, cryptographic implementations, and inter-service communications.
  • Advise clients on integrating code review, threat modeling, and security testing into SDLC processes, including CI/CD and pull-request workflows.
  • Represent the senior technical voice in client meetings, workshops, technical discussions, and developer training.
  • Mentor consultants and contribute to code review playbooks, tooling, methodologies, report templates, and application security research.
View Full Description & ApplyYou'll be redirected to the employer's site
US base salary range $75,000 - $175,000, depending on experience level, background and location.
Apply Now