Continuous Opening: Senior Application Security Pentester REMOTE

Independent Security Evaluators

• $115K — $165K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security consulting focused on application and software
  • Experience programming and developing exploits
  • Familiar with Unix command line tools and CLI environments
  • Advanced skills in web and desktop application security and cloud security
  • Experience in software vulnerability analysis and reverse engineering
  • Strong technical writing and oral communication skills
  • Public speaking experience

Responsibilities

  • Lead projects, interface directly with clients, and manage scoping
  • Mentor junior analysts through assessments and professional development
  • Perform hands-on security assessments across various technologies
  • Create detailed assessment reports identifying vulnerabilities and remediation
  • Advise clients on security best practices and emerging threats
  • Research and develop whitepapers and presentations on relevant topics
  • Participate in events like IoT Village

Benefits

  • Flexible schedule and remote work options
  • Unlimited vacation policy
  • $0 health premium plan for employees and dependents
  • Opportunities to present at major security conferences
  • Supportive leadership focused on mentorship and growth
  • Casual work environment with flexible workspace options
Full Job Description
Independent Security Evaluators (ISE) is continuously looking for Senior level Application Security Pentester/Analyst candidates. We are not currently hiring for this role, but we would still love to connect with you!

Do you enjoy working with wicked smart people, like to hack into things, solve puzzles, and work on cool projects? ISE is the place for you!

What you'll do at ISE:
  • Interface directly as a project lead, senior analyst, or in a scoping capacity
  • Mentor junior analysts throughout client assessments, research projects, findings reviews, and general professional and technical development
  • Perform hands-on security assessments and reviews on various pieces of technology including but not limited to:
    • Web apps and APIs
    • Mobile apps
    • Networks
    • Cloud architecture and configuration
    • Source code analysis
    • Hardware and firmware
  • Create comprehensive assessment reports that clearly identify vulnerabilities, how they impact our client's digital assets, and remediation strategies
  • Provide consultative advice to ISE's clients regarding best practices, design guidance, new threats, policies and processes, etc. Basically: be their genius friend who helps solve problems.
  • Perform research and develop whitepapers/presentations/etc. regarding relevant research, security topics, tools and techniques driven by your areas of interest and expertise
  • Opportunity to participate in IoT Village


What you won't do at ISE:
  • Use scanners - we might use a scanning tool on occasion but our assessments are designed to find what scanners miss
  • Write policy or compliance rules or assess tools for regulatory purposes
  • Only hack with your head down - we are looking for folks who will talk with our clients, mentor others, and collaborate on projects, talks, and research


What you bring to the table:
  • 6+ years in security consulting with a focus on application/software
  • Experience with programming and developing exploits
  • Familiarity with Unix command line tools and working in CLI environments
  • Skillset in the following:
    • Web and desktop application security (Advanced)
    • Cloud security and architecture (Advanced)
    • Mobile application security (Basic)
  • Background in the following:
    • Software vulnerability analysis, code analysis, and fuzzing
    • Reverse engineering through static and dynamic analysis
    • Analyzing cryptographic workflows
    • Analyzing network traffic
    • Experience interacting with clients in a consultative environment
  • Strong technical writing and oral communication skills
  • Public speaking experience
  • Desire to make things better: help our clients secure their products, help your colleagues grow and learn, self-motivated and always seeking improvement


Nice to have (but we can teach you!):
  • Skillset in the following:
    • IoT hardware security
    • Network security
    • Red Teaming
    • AI security
  • Experience with digital rights management and digital watermarking
  • Experience with secure software development
  • Familiarity with industry standard security policies (SOC2, OWASP ASVA, GDPR, ISO 27001, PCI, NIST CSF, etc) and their practical applications
  • Experience assessing generative AI technologies and applications


Salary:

$115K-$165K, according to experience

If you don't think you meet all of the criteria above but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team.

What we bring to the table:
  • Check out joinise.io for full details
  • Work that matters; projects that impact people's everyday life and wellbeing
  • Quality, integrity, dedication, and education: our core values
  • Life balance: flexible schedule, work from home options, unlimited vacation
  • $0 health premium plan option, including spouse and family
  • Opportunities to research and publish, speak at major security events and conferences
  • Leadership and peers that support and mentor you: your growth is our growth, your success is our success
  • Relaxed and fun environment: ditch the suit and tie, sit or stand at your desk or find a sofa

Similar Jobs

More Jobs at Independent Security Evaluators

More Information Technology Jobs

Find similar Continuous Opening: Senior Application Security Pentester REMOTE jobs: