IOActive logo
IOActivePosted 1 month ago

Associate Security Consultant

$40,000–$50,000 year

On-siteMadrid, Madrid, Spain

Full TimeEntry LevelAssociates DegreeSmall

Job Summary

Conduct application and infrastructure security assessments for web, mobile, and API systems using manual techniques and industry-standard tools. Identify vulnerabilities, misconfigurations, and deviations from best practices, then verify remediation actions to confirm fixes work as intended. Document findings, prepare professional reports with actionable recommendations, and participate in client meetings to discuss risks and business objectives. Collaborate with senior consultants, developers, and stakeholders across multiple industries while contributing to internal documentation and best practices. Continuously build knowledge of security concepts, tools, and emerging threats through internal research, lab exercises, and knowledge-sharing sessions.

Required Qualifications

  • 1-3 years of experience in offensive security services doing web, mobile and infrastructure penetration tests and vulnerability assessments
  • Good knowledge of common web, mobile, and infrastructure vulnerabilities as those described in OWASP Top 10 respective projects
  • Experience with security tools such as Burp Suite, OWASP ZAP, or Tenable Nessus
  • Understanding of operating systems concepts including Windows and GNU/Linux
  • Basic experience with scripting or programming languages (e.g. Python, Javascript, Bash, PowerShell, C/C++)
  • Knowledge of networking concepts and protocols
  • Familiarity with security testing methodologies
  • Bachelor's degree in computer science, Information Security, Information Technology, Software Engineering, or a related discipline, or equivalent practical experience

Desired Qualifications

  • Experience with cloud security best practices (AWS, Azure, Google) is valued but not required
  • Internship, academic, Capture the Flag (CTF), open-source, or personal project experience in cybersecurity is valued but not required
  • Knowledge of secure software development practices is valued but not required
  • Relevant certifications such as OSCP, OSWE, BSCP or similar offensive security trainings are a strong plus
  • A willingness to pursue additional professional certifications and ongoing technical development

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce