Independent Security Evaluators · 5 days ago
Continuous Opening: Senior Application Security Pentester REMOTE
Independent Security Evaluators is a security consulting and software firm dedicated to securing high value assets for global enterprises. They are looking to network with Senior level Application Security Pentester candidates who will perform hands-on security assessments, mentor junior analysts, and provide consultative advice to clients regarding security best practices.
Network Security
Responsibilities
Interface directly as a project lead, senior analyst, or in a scoping capacity
Mentor junior analysts throughout client assessments, research projects, findings reviews, and general professional and technical development
Perform hands-on security assessments and reviews on various pieces of technology including but not limited to:
Web apps and APIs
Mobile apps
Networks
Cloud architecture and configuration
Source code analysis
Hardware and firmware
Create comprehensive assessment reports that clearly identify vulnerabilities, how they impact our client’s digital assets, and remediation strategies
Provide consultative advice to ISE’s clients regarding best practices, design guidance, new threats, policies and processes, etc. Basically: be their genius friend who helps solve problems
Perform research and develop whitepapers/presentations/etc. regarding relevant research, security topics, tools and techniques driven by your areas of interest and expertise
Opportunity to participate in IoT Village
Qualification
Required
6+ years in security consulting with a focus on application/software
Experience with programming and developing exploits
Familiarity with Unix command line tools and working in CLI environments
Skillset in the following: Web and desktop application security (Advanced)
Skillset in the following: Cloud security and architecture (Advanced)
Skillset in the following: Mobile application security (Basic)
Background in the following: Software vulnerability analysis, code analysis, and fuzzing
Background in the following: Reverse engineering through static and dynamic analysis
Background in the following: Analyzing cryptographic workflows
Background in the following: Analyzing network traffic
Experience interacting with clients in a consultative environment
Strong technical writing and oral communication skills
Public speaking experience
Desire to make things better: help our clients secure their products, help your colleagues grow and learn, self-motivated and always seeking improvement
Preferred
Skillset in the following: IoT hardware security
Skillset in the following: Network security
Skillset in the following: Red Teaming
Skillset in the following: AI security
Experience with digital rights management and digital watermarking
Experience with secure software development
Familiarity with industry standard security policies (SOC2, OWASP ASVA, GDPR, ISO 27001, PCI, NIST CSF, etc) and their practical applications
Experience assessing generative AI technologies and applications
Benefits
$0 health premium plan option, including spouse and family
Flexible schedule
Work from home options
Unlimited vacation
Paid training
Workshops
University courses
Certification courses