Full Time
80,000
TBD
Feb 27, 2021
Responsibilities
- Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired and wireless networks, and mobile applications/devices
- Develop and maintain security testing plans
- Automate penetration and other security testing on networks, systems and applications
- Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk
- Produce actionable, threat-based, reports on security testing results
- Act as a source of direction, training, and guidance for less experienced staff
- Mentor and coach other IT security staff to provide guidance and expertise in their growth
- Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation
- Communicate security issues to a wide variety of internal and external “customers” to include technical teams, executives, risk groups, vendors and regulators
- Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests
- Foster and maintain relationships with key stakeholders and business partners
Requirements:
- 5+ yr of exp in Cybersecurity
- Proven expertise & track record in Network and system Penetration testing (Web, Mobile, API/Web Services)
- Be able to lead an assessment or penetration test with 1-2 other resources
- Be able to lead a red team engagement and participate in a purple team engagement.
- Be an expert in penetration testing methodology
- Have experience in developing exploits and tooling from vulnerabilities both pre and post exploitation.
- Should have experience with tools Burp suite, Metasploit, Tenable, SQL Map, NMAP, SCAPY, and other tools.
- Knowledge of OWASP Web and Mobile Top 10 vulnerabilities and identifying them.
- Knowledge of TCP/IP and other application and network level protocols.
- Conduct vulnerability assessment and penetration testing and configuration review for systems and networks.
- Be able to author and issue reports on assigned application and system scan.
- Support Jr. resources in their authoring of reports and issues.
- Support and recreate proofs of concept from security reports.
- Support and be a member of the PSIRT organization.
- Good exposure to Cloud Applications like AWS, Azure and other SAAS Applications
- Experience in Automating Security tasks using Python or Java Frameworks is a bonus
- Should be able to think ""Out of the box"". Possess ability to think and implement new attack approaches/vectors.
- Should be able to support the development of tooling for CI/CD/CS processes enabling other teams to test their own systems and work output.
- Should possess relevant university degree and/or professional qualifications/certification (e.g. CEH, OSCP)
- Be able to maintain and contribute to the threat models
- Support sessions to teach system and network exploitation and security testing methods to resources.
- Excellent written and verbal communication skills.
- Self-motivated, curious, knowledgeable pertaining to news and current events.