Associate Security Consultant

Posted 17 Days Ago
Be an Early Applicant
Madrid, Comunidad de Madrid, ESP
In-Office
40K-50K Annually
Junior
Security
The Role
Perform web, mobile, API, and infrastructure security assessments and penetration tests using manual techniques and tools. Identify, document, and validate vulnerabilities and remediation. Support client engagements, prepare reports, participate in meetings, collaborate with teams, and contribute to internal research, training, and methodology improvements.
Summary Generated by Built In
OUR MISSION UNITES US


"Making the world a safer and more secure place."


It’s our mission, plain and simple. It drives everything we do – from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn’t just “push the envelope” or “think outside the box.” We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.


About IOActive:

IOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.

Who you are

The Associate Security Consultant delivers application and infrastructure security services for clients across a variety of industries. Working alongside experienced consultants, this role actively participates in security assessments, web and mobile application reviews, infrastructure penetration tests, and security advisory engagements while developing technical consulting skills.

This is an excellent opportunity for someone with a strong interest in cybersecurity who enjoys problem solving, learning new technologies, and working with industry experts to improve software security.

 

What You'll Do

Security Assessments

  • Conduct application security assessments for web and mobile applications (Android/iOS), APIs, and other software systems.
  • Conduct infrastructure security reviews
  • Where suitable, deliver the above activities with support from more experienced consultants.
  • Carry out penetration testing activities using both manual techniques and industry-standard security tools.
  • Identify and document security vulnerabilities, misconfigurations and deviations from best practices, providing actionable recommendations to address them.
  • Verify and validate remediation actions to confirm fixes applied work as intended.

 Client Engagement

  • Contribute to client engagements by verifying testing prerequisites are met, collecting information, performing technical testing, and documenting findings.
  • Prepare clear, professional reports describing identified risks and recommended remediation steps.
  • Participate in client meetings and technical discussions alongside senior consultants.
  • Develop an understanding of client environments, technologies, and business objectives.

Collaboration

  • Work closely with other consultants on project delivery.
  • Collaborate with software developers, security teams, and project stakeholders from clients across multiple industries.
  • Share knowledge and contribute to internal documentation and best practices.
  • Participate in internal technical trainings.

  Professional Development

  • Continuously build knowledge of security concepts, tools, and emerging threats.
  • Participate in internal research, lab exercises, and knowledge-sharing sessions.
  • Stay current with security trends, vulnerabilities, and secure development practices.
  • Support continuous improvement of assessment methodologies and documentation. 

What You'll Bring

  • 1-3 years of experience in offensive security services doing web, mobile and infrastructure penetration tests and vulnerability assessments.
  • Good knowledge of common web, mobile, and infrastructure vulnerabilities as those described in OWASP Top 10 respective projects.
  • Experience with security tools such as Burp Suite, OWASP ZAP, or Tenable Nessus.
  • Understanding of operating systems concepts including Windows and GNU/Linux.
  • Basic experience with scripting or programming languages (e.g. Python, Javascript, Bash, PowerShell, C/C++).
  • Knowledge of networking concepts and protocols.
  • Familiarity with security testing methodologies.
  • Experience with cloud security best practices (AWS, Azure, Google) is valued but not required.
  • Internship, academic, Capture the Flag (CTF), open-source, or personal project experience in cybersecurity is valued but not required.
  • Knowledge of secure software development practices is valued but not required.
  • Strong analytical and problem-solving abilities.
  • Curiosity and enthusiasm for learning new technologies.
  • Good written and verbal English communication skills.
  • Ability to explain technical concepts clearly.
  • Strong attention to detail.
  • Ability to work independently while collaborating effectively within a team.
  • Professionalism when interacting with clients and colleagues.
  • Strong organizational and time management skills.
  • Bachelor’s degree in computer science, Information Security, Information Technology, Software Engineering, or a related discipline, or equivalent practical experience.
  • Relevant certifications such as OSCP, OSWE, BSCP or similar offensive security trainings are a strong plus.
  • A willingness to pursue additional professional certifications and ongoing technical development.

What We Offer 

🎯 A chance to work with an industry leader in cyber security

💡 Access to world-class technical teams and research

🏆 A high-energy, collaborative team that values innovation

💻 Flexibility—work remotely or from the office as needed

✈️ Opportunities for travel

💰 Competitive compensation range targeted €40,000 - €50,000

 

If this sounds like your kind of challenge, we’d love to hear from you. Let’s talk!


Why IOActive:


We have over 25 years of experience that’s established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space. We're one of “the good guys” doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.

 

IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.

 

This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Skills Required

  • 1-3 years of experience in offensive security services, including web, mobile, and infrastructure penetration testing and vulnerability assessments
  • Knowledge of common web, mobile, and infrastructure vulnerabilities (OWASP Top 10 and related projects)
  • Experience with security tools such as Burp Suite, OWASP ZAP, or Tenable Nessus
  • Understanding of operating systems concepts including Windows and GNU/Linux
  • Basic experience with scripting or programming languages (Python, Javascript, Bash, PowerShell, C/C++)
  • Knowledge of networking concepts and protocols
  • Familiarity with security testing methodologies
  • Good written and verbal English communication skills; ability to explain technical concepts clearly
  • Bachelor's degree in computer science, information security, IT, software engineering, or equivalent practical experience
  • Experience with cloud security best practices (AWS, Azure, Google)
  • Internship, academic, CTF, open-source, or personal project experience in cybersecurity
  • Knowledge of secure software development practices
  • Relevant certifications such as OSCP, OSWE, BSCP or similar offensive security trainings
  • Willingness to pursue additional professional certifications and ongoing technical development
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Seattle, WA
118 Employees
Year Founded: 1998

What We Do

IOActive is the only security consultancy with a global presence and deep expertise in hardware, software, and wetware assessments. Our mission is to make certain your enterprise is more secure in an era of pervasive and emerging threats.

Similar Jobs

Expedia Group Logo Expedia Group

Sr Country Manager - TAAP FR, BE, NL

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Madrid, Comunidad de Madrid, ESP
16000 Employees
69K-110K Annually

Celonis Logo Celonis

Product Manager

Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Hybrid
Madrid, Comunidad de Madrid, ESP
3000 Employees

Celonis Logo Celonis

Finance & Cash Collection Specialist (German-Speaking)

Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Hybrid
Madrid, Comunidad de Madrid, ESP
3000 Employees

Mastercard Logo Mastercard

Manager, Open Finance Sales Western Europe (Spanish speaking)

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Madrid, Comunidad de Madrid, ESP
38800 Employees

Similar Companies Hiring

Closinglock Thumbnail
Fintech • Real Estate • Security • Software • Financial Services • Cybersecurity • PropTech
Austin, TX
110 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account