
Penetration Testing Engineer, MTS
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in California, +2 more states.
β’ Conduct penetration tests on web applications, APIs, and cloud/hybrid infrastructures, including Kubernetes and Docker, as well as identity and trust boundaries, and AI/ML-enabled systems.
β’ Assess AI/ML systems for prompt injection vulnerabilities and potential abuse of AI integrations.
β’ Execute manual exploitation beyond automated tools, focusing on business logic exploitation, privilege escalation, and abuse of identity/access trust relationships.
β’ Provide support for engagements through scoping, execution, risk assessment, and detailed reporting with guidance for remediation.
β’ Create comprehensive technical reports detailing exploitation paths, absent security controls, and recommendations for mitigation.
β’ Collaborate with engineering, AppSec, and Detection & Response teams regarding findings.
β’ Operate under the supervision of senior team members during complex engagements.
β’ Enhance skills across cloud, identity, and AI/ML attack surfaces.
β’ 2-4 years of practical experience in penetration testing, offensive security, or application security testing.
β’ Proven experience in conducting penetration testing engagements within production or production-like environments.
β’ Proficiency in both manual techniques and automation/AI tools.
β’ Knowledge of application security vulnerabilities and their respective attack chains.
β’ Familiarity with identity and access control weaknesses.
β’ Understanding of the fundamentals of cloud security.
β’ Awareness of security risks associated with AI and LLM-based systems.
β’ Capability to effectively communicate exploitation mechanics, impact, and actionable remediation steps to engineers and security teams.
β’ Experience in developing custom scripts, payloads, or proofs of concept is an advantage.
β’ Involvement in Bug Bounty programs is a plus.
β’ Understanding of cloud architectures and identity-centric security models is beneficial.
β’ Experience utilizing AI/LLMs for offensive security operations or vulnerability discovery is a plus.
β’ Time off programs
β’ Medical insurance
β’ Dental insurance
β’ Vision insurance
β’ Mental health support
β’ Paid parental leave
β’ Life insurance
β’ Disability insurance
β’ 401(k)
β’ Employee stock purchasing program
β’ Incentive compensation may be available for certain roles
β’ Equity may be available for certain roles
β’ Reasonable accommodations during the application or recruiting process
Etterli Testkaufdienst
Northline Seafoods
Scribe
CXM Direct
Get handpicked remote jobs straight to your inbox weekly.