06 ago
|
IOActive
|
Madrid
ppb"Making the world a safer and more secure place." /b " /p /brpIt’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our general team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us. /p /brh3About IOActive: /h3 /brpIOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK. /p /brh3Who you are /h3 /brpThe Associate Security Consultant delivers application and infrastructure security services for clients across a variety of industries. Working alongside experienced consultants, this role actively participates in security assessments, web and mobile application reviews, infrastructure penetration tests and security advisory engagements while developing technical consulting skills. /p /brpThis is an excellent opportunity for someone with a strong interest in cybersecurity who enjoys problem solving, learning new technologies and working with industry experts to improve software security. /p /brh3What You’ll Do /h3 /brh3Security Assessments /h3 /brul /brliConduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems. /li /brliConduct infrastructure security reviews /li /brliWhere suitable, deliver the above activities with support from more experienced consultants. /li /brliCarry out penetration testing activities using both manual techniques and industry‑standard security tools. /li /brliIdentify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them. /li /brliVerify and validate remediation actions to confirm fixes applied work as intended.
/li /br /ul /brh3Client Engagement /h3 /brul /brliContribute to client engagements by verifying testing prerequisites are met, collecting information, performing technical testing, and documenting findings. /li /brliPrepare clear, professional reports describing identified risks and recommended remediation steps. /li /brliParticipate in client meetings and technical discussions alongside senior consultants. /li /brliDevelop an understanding of client environments, technologies and business objectives. /li /brliWork closely with other consultants on project delivery. /li /brliCollaborate with software developers, security teams and project stakeholders from clients across multiple industries. /li /brliShare knowledge and contribute to internal documentation and best practices. /li /brliParticipate in internal technical trainings. /li /br /ul /brh3Professional Development /h3 /brul /brliContinuously build knowledge of security concepts, tools and emerging threats. /li /brliParticipate in internal research, lab exercises and knowledge‑sharing sessions. /li /brliStay current with security trends, vulnerabilities and secure development practices. /li /brliSupport continuous improvement of assessment methodologies and documentation. /li /br /ul /brh3What You’ll Bring /h3 /brul /brli1‑3 years of experience in offensive security services doing web, mobile and infrastructure penetration tests and vulnerability assessments. /li /brliGood knowledge of common web, mobile and infrastructure vulnerabilities as those described in OWASP Top 10 respective projects. /li /brliExperience with security tools such as Burp Suite, OWASP ZAP, or Tenable Nessus. /li /brliUnderstanding of operating systems concepts including Windows and GNU/Linux. /li /brliKnowledge of networking concepts and protocols. /li /brliFamiliarity with security testing methodologies. /li /brliExperience with cloud security best practices (AWS, Azure, Google) is valued but not required. /li /brliInternship, academic, Capture the Flag (CTF), open‑source or personal project experience in cybersecurity is valued but not required. /li /brliKnowledge of secure software development practices is valued but not required .
/li /brliStrong analytical and problem‑solving abilities. /li /brliCuriosity and enthusiasm for learning new technologies. /li /brliGood written and verbal English communication skills. /li /brliAbility to explain technical concepts clearly. /li /brliStrong attention to detail. /li /brliAbility to work independently while collaborating effectively within a team. /li /brliProfessionalism when interacting with clients and colleagues. /li /brliStrong organizational and time management skills. /li /brliBachelor’s degree in computer science, Information Security, Information Technology, Software Engineering or a related discipline or equivalent practical experience. /li /brliRelevant certifications such as OSCP, OSWE, BSCP or similar offensive security trainings are a strong plus. /li /brliA willingness to pursue additional professional certifications and ongoing technical development. /li /br /ul /brh3What We Offer /h3 /brul /brliA chance to work with an industry leader in cyber security /li /brliAccess to world‑class technical teams and research /li /brliA high‑energy collaborative team that values innovation /li /brliFlexibility—work remotely or from the office as needed /li /brliOpportunities for travel /li /br /ul /brh3Why IOActive: /h3 /brpWe have over 25 years of experience that’s established and stable; yet high‑growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high‑profile, cutting edge space. We’re one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter. /p /brpIOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy or any other protected characteristic as outlined by federal, state, or local laws. /p /brpThis policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, leave of absence, compensation, benefits, training and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit and business needs at the time. /p /p #J-18808-Ljbffr
📌 Associate Security Consultant (Madrid)
🏢 IOActive
📍 Madrid