Lead Penetration Test Engineer

Posted Sep 10

This is a fully remote position, open to applicants in United States, +10 more locations.

📋 Description

• Execute thorough penetration testing on web applications, infrastructure, and cloud environments.

• Conduct re-testing, vulnerability scans, and threat assessments across various environments.

• Create custom scripts, tools, and methodologies to enhance penetration testing and automate security testing within CI/CD pipelines.

• Utilize cloud offensive techniques, including IAM abuse, container and serverless exploitation, and testing for cloud misconfigurations.

• Work collaboratively with engineering and development teams on vulnerability analysis, remediation strategies, and application security.

• Carry out DAST, SAST, and SCA security evaluations.

• Lead and engage in attack simulations and tabletop exercises.

• Investigate emerging threats, attack vectors, and adversarial tactics.

• Design and implement threat assessments utilizing intelligence feeds and threat actor analysis.

• Communicate findings to both technical and non-technical stakeholders.

• Offer remediation advice and risk mitigation strategies.


⛳️ Requirements

• At least 8 years of experience in information security, with a focus on penetration testing, application security, and vulnerability management.

• Practical experience with tools such as Burp Suite, Nessus, Metasploit, and Nmap.

• Familiarity with OWASP Top 10, MITRE ATT&CK, and PTES frameworks.

• Proficiency in identifying and exploiting infrastructure and web application vulnerabilities, including XSS, SQL Injection, and IDOR.

• Understanding of CVE, CVSS, and CWE.

• Strong scripting or programming abilities in languages such as Bash, Python, Go, PowerShell, or JavaScript.

• Experience with DAST, SAST, SCA, credential scanning, and the integration of security into CI/CD processes.

• Capability to convey technical findings through actionable reports and effectively brief cross-functional teams and executives.

• Possession of at least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT.

• A Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience.

• US-based candidates must possess an indefinite right to work in the US; Canada-based candidates must have an indefinite right to work in Canada.


🏝️ Benefits

• Comprehensive health care coverage designed for both mental and physical well-being.

• Generous time-off policy.

• Access to continuous learning resources and career development opportunities.

• Competitive salary.

• Retirement planning options.

• Continuing education program with company-matched student loan contributions.

• Financial wellness initiatives.

• Family-oriented benefits and perks.

• Discounts at retail partners.

• Referral incentive awards.

People also viewed

Converge Insurance1 day ago

Senior Software Engineer in Test

BR flagBrazil, +3 more countriesFreelanceSoftware Development Engineer in Test (SDET)$5,000 – $9,000/month
ApplyView job
CACI International Inc1 day ago

Software Test Engineer

US flagIllinois OnlyFull-timeSoftware Development Engineer in Test (SDET)$75.2k – $158.1k/year
ApplyView job
MagmaLabs1 day ago

QA Automation Engineer, Robot Framework

MX flagMexico OnlyFreelanceSoftware Development Engineer in Test (SDET)
ApplyView job
Upgrade, Inc.1 day ago

Senior QA Automation Engineer – HELOC

US flagUnited States OnlyFull-timeSoftware Development Engineer in Test (SDET)
ApplyView job
Estoras Group1 day ago

QA Automation Specialist

CA flagCanada, +1 more countryFreelanceSoftware Development Engineer in Test (SDET)
ApplyView job
IndieKidz GmbH1 day ago

Software Test Automation Engineer – Internship (Unpaid)

DE flagGermany OnlyInternshipSoftware Development Engineer in Test (SDET)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers