Penetration Testing Engineer, MTS

Posted 4 days ago

This is a fully remote position, open to applicants in California, +2 more states.

πŸ“‹ Description

β€’ Conduct penetration tests on web applications, APIs, and cloud/hybrid infrastructures, including Kubernetes and Docker, as well as identity and trust boundaries, and AI/ML-enabled systems.

β€’ Assess AI/ML systems for prompt injection vulnerabilities and potential abuse of AI integrations.

β€’ Execute manual exploitation beyond automated tools, focusing on business logic exploitation, privilege escalation, and abuse of identity/access trust relationships.

β€’ Provide support for engagements through scoping, execution, risk assessment, and detailed reporting with guidance for remediation.

β€’ Create comprehensive technical reports detailing exploitation paths, absent security controls, and recommendations for mitigation.

β€’ Collaborate with engineering, AppSec, and Detection & Response teams regarding findings.

β€’ Operate under the supervision of senior team members during complex engagements.

β€’ Enhance skills across cloud, identity, and AI/ML attack surfaces.


⛳️ Requirements

β€’ 2-4 years of practical experience in penetration testing, offensive security, or application security testing.

β€’ Proven experience in conducting penetration testing engagements within production or production-like environments.

β€’ Proficiency in both manual techniques and automation/AI tools.

β€’ Knowledge of application security vulnerabilities and their respective attack chains.

β€’ Familiarity with identity and access control weaknesses.

β€’ Understanding of the fundamentals of cloud security.

β€’ Awareness of security risks associated with AI and LLM-based systems.

β€’ Capability to effectively communicate exploitation mechanics, impact, and actionable remediation steps to engineers and security teams.

β€’ Experience in developing custom scripts, payloads, or proofs of concept is an advantage.

β€’ Involvement in Bug Bounty programs is a plus.

β€’ Understanding of cloud architectures and identity-centric security models is beneficial.

β€’ Experience utilizing AI/LLMs for offensive security operations or vulnerability discovery is a plus.


🏝️ Benefits

β€’ Time off programs

β€’ Medical insurance

β€’ Dental insurance

β€’ Vision insurance

β€’ Mental health support

β€’ Paid parental leave

β€’ Life insurance

β€’ Disability insurance

β€’ 401(k)

β€’ Employee stock purchasing program

β€’ Incentive compensation may be available for certain roles

β€’ Equity may be available for certain roles

β€’ Reasonable accommodations during the application or recruiting process

People also viewed

Etterli Testkaufdienst1 day ago

Mystery Shopper – Quality Assurance

CH flagSwitzerland OnlyPart-timeQA Engineer (Quality Assurance)
ApplyView job
Northline Seafoods1 day ago

Quality Assurance Technician

US flagWashington OnlyFull-timeQA Engineer (Quality Assurance)$24 – $29/year
ApplyView job
Scribe1 day ago

Engineering Manager, QA

US flagUnited States OnlyFull-timeQA Engineer (Quality Assurance)$150k – $220k/year
ApplyView job
CXM Direct1 day ago

Full Stack QA Engineer – Forex Experienced

CY flagCyprus, +3 more countriesFull-timeQA Engineer (Quality Assurance)
ApplyView job
Just Eat Takeaway.com2 days ago

Senior Quality Engineer

CA flagCanada OnlyFull-timeQA Engineer (Quality Assurance)C$108k – C$128.3k/year
ApplyView job
It's Prodigy2 days ago

Software Tester – QA

IT flagItaly OnlyFull-timeQA Engineer (Quality Assurance)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers