
Lead Penetration Test Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in United States, +10 more locations.
• Perform thorough penetration testing on web applications, infrastructure, and cloud environments utilizing both manual and automated methods.
• Create custom scripts, tools, and methodologies to improve penetration testing and automate security assessments in CI/CD pipelines.
• Implement cloud-specific offensive strategies, including IAM abuse, exploitation of containers and serverless architectures, and testing for cloud misconfigurations.
• Work collaboratively with engineering and development teams to assess vulnerabilities, formulate remediation plans, and enhance application security.
• Conduct DAST, SAST, and SCA security evaluations.
• Lead and actively engage in attack simulations and tabletop exercises.
• Investigate emerging threats, attack vectors, and adversarial tactics.
• Design and carry out threat assessments utilizing intelligence feeds and threat actor analysis.
• Communicate penetration testing and security assessment results to both technical and non-technical stakeholders.
• Offer remediation advice and strategies for risk mitigation.
• At least 8 years of experience in information security, with a strong emphasis on penetration testing, application security, and vulnerability management.
• Practical experience with Burp Suite, Nessus, Metasploit, and Nmap.
• Familiarity with the OWASP Top 10, MITRE ATT&CK, and PTES methodologies.
• Proficient in identifying and exploiting vulnerabilities in infrastructure and web applications, including XSS, SQL Injection, and IDOR.
• Understanding of CVE, CVSS, and CWE frameworks.
• Strong programming or scripting skills in Bash, Python, Go, PowerShell, or JavaScript.
• Experience with DAST, SAST, SCA, credential scanning, and integrating security into CI/CD pipelines.
• Capable of conveying technical findings through clear reports and briefings to cross-functional teams and executives.
• Possession of at least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT.
• Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience.
• Candidates in the US must have an indefinite right to work in the US.
• Candidates in Canada must have an indefinite right to work in Canada.
• Comprehensive health care coverage focused on mental and physical well-being.
• Generous paid time off.
• Access to continuous learning resources.
• Competitive compensation.
• Retirement planning assistance.
• Continuing education program with company-matched contributions for student loans.
• Financial wellness initiatives.
• Family benefits for partners and children.
• Discounts at various retail outlets.
• Incentives for employee referrals.
Converge Insurance
CACI International Inc
MagmaLabs
Upgrade, Inc.
Get handpicked remote jobs straight to your inbox weekly.