Senior Security Consultant, Application Security
I
IOActiveCybersecurity consulting
BrazilFull-TimeSenior
SalaryUS base salary range $75,000 - $175,000, depending on experience level, background and location.
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review
- Required Skills
- PythonJavaJavascriptTypeScript
Requirements
- Have 5+ years of experience in offensive security services, including at least 2–3 years focused on application security and source code review.
- Bring hands-on engagement delivery experience across code review, application penetration testing, threat modeling, or SDLC consulting.
- Have deep code review expertise in at least two of JavaScript/TypeScript, Python, Java, C#/.NET, C/C++, Rust, or Go.
- Understand common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and their security pitfalls.
- Have a relevant bachelor's degree or equivalent experience.
- Relevant industry certifications are strongly preferred, such as OSCP, OSWE, GWAPT, CSSLP, or GWEB.
- Familiarity with OWASP ASVS, NIST SSDF, BSIMM, or SAMM is a plus.
- Be able to produce clear written reports and present technical findings to developer and general audiences.
- Be comfortable working across languages and technology stacks and collaborating with delivery teams and client developers.
Responsibilities
- Lead manual source code reviews on complex production codebases across web applications, mobile backends, APIs, and embedded systems.
- Identify common and nuanced vulnerabilities, and write findings reports with remediation guidance, proof-of-concepts where appropriate, and architectural recommendations.
- Lead developer workshops to explain findings and security patterns.
- Perform application penetration testing across web, API, and mobile targets.
- Conduct threat modeling and secure design reviews of architectures, authentication systems, cryptographic implementations, and inter-service communications.
- Advise clients on integrating code review, threat modeling, and security testing into SDLC processes, including CI/CD and pull-request workflows.
- Represent the senior technical voice in client meetings, workshops, technical discussions, and developer training.
- Mentor consultants and contribute to code review playbooks, tooling, methodologies, report templates, and application security research.
View Full Description & ApplyYou'll be redirected to the employer's site