
Lead Penetration Test Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in United States, +10 more locations.
• Execute thorough penetration testing on web applications, infrastructure, and cloud environments.
• Conduct re-testing, vulnerability scans, and threat assessments across various environments.
• Create custom scripts, tools, and methodologies to enhance penetration testing and automate security testing within CI/CD pipelines.
• Utilize cloud offensive techniques, including IAM abuse, container and serverless exploitation, and testing for cloud misconfigurations.
• Work collaboratively with engineering and development teams on vulnerability analysis, remediation strategies, and application security.
• Carry out DAST, SAST, and SCA security evaluations.
• Lead and engage in attack simulations and tabletop exercises.
• Investigate emerging threats, attack vectors, and adversarial tactics.
• Design and implement threat assessments utilizing intelligence feeds and threat actor analysis.
• Communicate findings to both technical and non-technical stakeholders.
• Offer remediation advice and risk mitigation strategies.
• At least 8 years of experience in information security, with a focus on penetration testing, application security, and vulnerability management.
• Practical experience with tools such as Burp Suite, Nessus, Metasploit, and Nmap.
• Familiarity with OWASP Top 10, MITRE ATT&CK, and PTES frameworks.
• Proficiency in identifying and exploiting infrastructure and web application vulnerabilities, including XSS, SQL Injection, and IDOR.
• Understanding of CVE, CVSS, and CWE.
• Strong scripting or programming abilities in languages such as Bash, Python, Go, PowerShell, or JavaScript.
• Experience with DAST, SAST, SCA, credential scanning, and the integration of security into CI/CD processes.
• Capability to convey technical findings through actionable reports and effectively brief cross-functional teams and executives.
• Possession of at least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT.
• A Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience.
• US-based candidates must possess an indefinite right to work in the US; Canada-based candidates must have an indefinite right to work in Canada.
• Comprehensive health care coverage designed for both mental and physical well-being.
• Generous time-off policy.
• Access to continuous learning resources and career development opportunities.
• Competitive salary.
• Retirement planning options.
• Continuing education program with company-matched student loan contributions.
• Financial wellness initiatives.
• Family-oriented benefits and perks.
• Discounts at retail partners.
• Referral incentive awards.
Converge Insurance
CACI International Inc
MagmaLabs
Upgrade, Inc.
Get handpicked remote jobs straight to your inbox weekly.