Lead Penetration Test Engineer

Posted Sep 10

This is a fully remote position, open to applicants in United States, +10 more locations.

📋 Description

• Perform thorough penetration testing on web applications, infrastructure, and cloud environments utilizing both manual and automated methods.

• Create custom scripts, tools, and methodologies to improve penetration testing and automate security assessments in CI/CD pipelines.

• Implement cloud-specific offensive strategies, including IAM abuse, exploitation of containers and serverless architectures, and testing for cloud misconfigurations.

• Work collaboratively with engineering and development teams to assess vulnerabilities, formulate remediation plans, and enhance application security.

• Conduct DAST, SAST, and SCA security evaluations.

• Lead and actively engage in attack simulations and tabletop exercises.

• Investigate emerging threats, attack vectors, and adversarial tactics.

• Design and carry out threat assessments utilizing intelligence feeds and threat actor analysis.

• Communicate penetration testing and security assessment results to both technical and non-technical stakeholders.

• Offer remediation advice and strategies for risk mitigation.


⛳️ Requirements

• At least 8 years of experience in information security, with a strong emphasis on penetration testing, application security, and vulnerability management.

• Practical experience with Burp Suite, Nessus, Metasploit, and Nmap.

• Familiarity with the OWASP Top 10, MITRE ATT&CK, and PTES methodologies.

• Proficient in identifying and exploiting vulnerabilities in infrastructure and web applications, including XSS, SQL Injection, and IDOR.

• Understanding of CVE, CVSS, and CWE frameworks.

• Strong programming or scripting skills in Bash, Python, Go, PowerShell, or JavaScript.

• Experience with DAST, SAST, SCA, credential scanning, and integrating security into CI/CD pipelines.

• Capable of conveying technical findings through clear reports and briefings to cross-functional teams and executives.

• Possession of at least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT.

• Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience.

• Candidates in the US must have an indefinite right to work in the US.

• Candidates in Canada must have an indefinite right to work in Canada.


🏝️ Benefits

• Comprehensive health care coverage focused on mental and physical well-being.

• Generous paid time off.

• Access to continuous learning resources.

• Competitive compensation.

• Retirement planning assistance.

• Continuing education program with company-matched contributions for student loans.

• Financial wellness initiatives.

• Family benefits for partners and children.

• Discounts at various retail outlets.

• Incentives for employee referrals.

People also viewed

Converge Insurance1 day ago

Senior Software Engineer in Test

BR flagBrazil, +3 more countriesFreelanceSoftware Development Engineer in Test (SDET)$5,000 – $9,000/month
ApplyView job
CACI International Inc1 day ago

Software Test Engineer

US flagIllinois OnlyFull-timeSoftware Development Engineer in Test (SDET)$75.2k – $158.1k/year
ApplyView job
MagmaLabs1 day ago

QA Automation Engineer, Robot Framework

MX flagMexico OnlyFreelanceSoftware Development Engineer in Test (SDET)
ApplyView job
Upgrade, Inc.1 day ago

Senior QA Automation Engineer – HELOC

US flagUnited States OnlyFull-timeSoftware Development Engineer in Test (SDET)
ApplyView job
Estoras Group1 day ago

QA Automation Specialist

CA flagCanada, +1 more countryFreelanceSoftware Development Engineer in Test (SDET)
ApplyView job
IndieKidz GmbH1 day ago

Software Test Automation Engineer – Internship (Unpaid)

DE flagGermany OnlyInternshipSoftware Development Engineer in Test (SDET)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers