Senior Application Security Pentester
Job Description
Independent Security Evaluators (ISE) supports security professionals who want to do hands-on application testing with real-world impact. This senior role is built around meaningful client assessments, research, and collaboration, backed by a flexible schedule, work from home options, and unlimited vacation. ISE also offers a $0 health premium plan option, including coverage for a spouse and family, plus opportunities to research and publish and speak at major security events and conferences. The environment is relaxed and team-led, with a culture that encourages mentorship and continuous improvement.
Responsibilities
- Serve as a project lead, senior analyst, or in a scoping capacity for client engagements
- Mentor junior analysts across client assessments, research projects, findings reviews, and professional and technical development
- Conduct hands-on security assessments and reviews across technology domains, including:
- Web applications and APIs
- Mobile applications
- Networks
- Cloud architecture and configuration
- Source code analysis
- Hardware and firmware
- Produce comprehensive assessment reports that identify vulnerabilities, explain their impact on clients' digital assets, and outline remediation strategies
- Provide consultative guidance to clients on best practices, design guidance, and emerging threats, along with relevant policies and processes
- Perform research and develop whitepapers, presentations, and other materials aligned to research interests and expertise
- Opportunity to participate in IoT Village
Requirements
- 6+ years in security consulting focused on application or software
- Experience with programming and developing exploits
- Familiarity with Unix command line tools and working in CLI environments
- Advanced skillset in web and desktop application security
- Advanced skillset in cloud security and architecture
- Basic skillset in mobile application security
- Background in software vulnerability analysis, code analysis, and fuzzing
- Background in reverse engineering through static and dynamic analysis
- Background in analyzing cryptographic workflows
- Background in analyzing network traffic
- Experience interacting with clients in a consultative environment
- Strong technical writing and oral communication skills
- Public speaking experience
- Desire to make things better through help for clients and growth for colleagues, along with self-motivation and a continuous improvement mindset
Salary and location
Location: Baltimore, MD (remote)
Compensation: $115,000 - $165,000 per year, depending on experience
What you won't do at ISE
- Rely on scanners as the primary approach (scanning tools may be used occasionally, but assessments are designed to find what scanners miss)
- Write policy or compliance rules or assess tools strictly for regulatory purposes
- Work only “head down” without client interaction (the role includes discussion with clients, mentoring, and collaboration on projects, talks, and research)
Nice to have
- IoT hardware security
- Network security
- Red Teaming
- AI security
- Experience with digital rights management and digital watermarking
- Experience with secure software development
- Familiarity with industry standard security policies and practical applications (SOC2, OWASP ASVA, GDPR, ISO 27001, PCI, NIST CSF, etc.)
- Experience assessing generative AI technologies and applications
Benefits
- Flexible schedule
- Work from home options
- Unlimited vacation
- $0 health premium plan option, including spouse and family
- Opportunities to research and publish, and to speak at major security events and conferences
- Leadership and peers that support and mentor you (your growth is their growth; your success is their success)
- Relaxed and fun environment: ditch the suit and tie, sit or stand at your desk, or find a sofa
Note: ISE is connecting with Senior level Application Security Pentester/Analyst candidates and is not currently hiring for this role.