9,811 Security Testing jobs in the United States
Operations, Security Testing & Reporting Lead

Posted 3 days ago
Job Viewed
Job Description
Operations Lead, Cyber Defense Data and Application Security
**Collaborate with Innovative 3Mers Around the World**
Choosing where to start and grow your career has a major impact on your professional and personal life, so it's equally important you know that the company that you choose to work at, and its leaders, will support and guide you. With a wide variety of people, global locations, technologies and products, 3M is a place where you can collaborate with other curious, creative 3Mers.
**This position provides an opportunity to transition from other private, public, government or military experience to a 3M career.**
**The Impact You Will Make in this Role**
As the Operations & Reporting Lead in the Cyber Defense team at our global manufacturing company, you will oversee financial and operational reporting, data governance, budget planning, resource allocation, and the management of our application security testing program. You'll partner closely with Finance, IT Security, Engineering, and Business Unit leaders to ensure data integrity, cost-effective operations, and robust security validation of critical applications.
Key Responsibilities:
+ Develop, maintain, and distribute monthly/quarterly operational and financial dashboards to senior leadership
+ Design ad-hoc reports and analyses to support business decision-making
+ Ensure accuracy and timeliness of KPI tracking (production throughput, quality metrics, security testing outcomes)
+ Align with 3M data standards, taxonomies, and data quality processes
+ Develop a Cyber Defense data strategy to support management and operational decision making and reporting
+ Manage Cyber Defense data quality, support corrective actions as necessary, and implement improvements
+ Own the annual operating and capital budget for reporting, data management, and security testing activities
+ Track actuals vs. budget; analyze variances and present recommendations for cost optimization
+ Partner with Finance to forecast resource and tool investments for the coming fiscal year
+ Plan headcount, contractors, and vendor engagements to meet operational and testing needs
+ Conduct quarterly capacity reviews and adjust resourcing plans to align with project pipelines
+ Mentor and develop a team of analysts, data stewards, and security-testing coordinators
+ Evolve the current application security testing program
+ Manage the pipeline of static, dynamic, and interactive application-security tests (SAST, DAST, IAST)
+ Build and maintain relationships with third-party security testing vendors and ensure SLA adherence
**Your Skills and Expertise**
To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:
+ Bachelor's degree in Business Administration, Information Systems, Finance, or Computer Science (completed and verified prior to start)
+ Five (5) years of operations or project management experience in a manufacturing or highly regulated industry in a private, public, government or military environment
Additional qualifications that could help you succeed even further in this role include:
+ Master's degree (MBA or MS in Information Systems)
+ Experience in global rollouts and cross-cultural team leadership
+ Certifications: PMP, CISSP, CISA, CISM, or Security+ Proven expertise in financial reporting, budget management, and data governance frameworks
+ Understanding of application security testing methodologies and tools
+ Proficiency with BI tools (e.g., Power BI, Tableau)
+ Excellent leadership, communication, and stakeholder management skills
**Work location: On site in** **Austin TX**
**Travel:** **May include up to 10** **% domestic and international**
**Relocation Assistance:** **Is Authorized**
**Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).**
**Supporting Your Well-being**
3M offers many programs to help you live your best life - both physically and financially. To ensure competitive pay and benefits, 3M regularly benchmarks with other companies that are comparable in size and scope.
**Chat with Max**
For assistance with searching through our current job openings or for more information about all things 3M, visit Max, our virtual recruiting assistant on 3M.com/careers.
Applicable to US Applicants Only:The expected compensation range for this position is $188,251 - $230,084, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate's relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: Faith Posting Date Range 07/16/2025 To 08/15/2025 Or until filled
All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or equivalent and above may also have obligations to not compete against 3M or solicit its employees or customers, both during their employment, and for a period after they leave 3M.
Learn more about 3M's creative solutions to the world's problems at or on Instagram, Facebook, and LinkedIn @3M.
Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties.
Safety is a core value at 3M. All employees are expected to contribute to a strong EHS culture by following safety policies, identifying hazards, and engaging in continuous improvement.
Pay & Benefits Overview: does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
**Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.**
**3M Global Terms of Use and Privacy Statement**
Carefully read these Terms of Use before using this website. Your access to and use of this website and application for a job at 3M are conditioned on your acceptance and compliance with these terms.
Please access the linked document by clicking here ( , select the country where you are applying for employment, and review. Before submitting your application, you will be asked to confirm your agreement with the terms.
At 3M we apply science in collaborative ways to improve lives daily as our employees connect with customers all around the world. Learn more about 3M's creative solutions to global challenges at or on Twitter @3M or @3MNews.
3M does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
FLEX Application Security Testing Analyst

Posted 4 days ago
Job Viewed
Job Description
**Job Number** 25088041
**Job Category** Information Technology
**Location** Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States, 20814VIEW ON MAP ( Full Time
**Located Remotely?** N
**Position Type** Management
This is a temporary position.
The Application Security Testing Analyst will support the assessment and improvement of Web, API, Mobile application security through hands-on security testing and code analysis. The ideal candidate will have a solid foundation in secure coding practices, vulnerability detection, and testing techniques such as SAST, DAST, and manual testing. This role is designed to offer practical experience in application security testing, with opportunities to work directly with development teams, security tools, and automation in real-world environments.
**CANDIDATE PROFILE**
**Education and Experience**
**Required:**
+ Bachelor's degree in Cybersecurity, Computer Science or related field or equivalent experience/certification
+ 2+ years of information technology or application development experience
+ Strong understanding of programming concepts (e.g., loops, data types, logic, input/output)
+ Basic experience or familiarity with application security testing tools (e.g., Burp Suite, OWASP ZAP, Fortify, Veracode)
+ Understanding of the OWASP Top 10 and common application vulnerabilities (e.g., XSS, SQLi, CSRF)
+ Basic knowledge of vulnerability triage and remediation processes
+ Familiarity with version control (e.g., Git), CI/CD concepts, and the SDLC
+ Proficiency in Microsoft Word, PowerPoint, and Excel
+ Excellent communication skills
**Preferred:**
+ Master's degree in Cybersecurity, Computer Science, or related field or equivalent experience/certification
+ Security certifications (e.g., GWAPT, OSCP, CEH, Security+, or CySA+)
+ 2+ years of experience in an application security, QA, or software testing role
+ Experience performing web application penetration testing or source code review
+ Exposure to secure SDLC practices and integrating testing into CI/CD pipelines
+ Understanding of risk scoring frameworks (e.g., CVSS) and security ticketing workflows
+ Familiarity with compliance standards such as PCI-DSS, NIST 800-53, or ISO 27001
**CORE WORK ACTIVITIES**
**Application Security Risk Management & Tracking**
+ Application Security Testing & Risk Analysis
+ Assist with static and dynamic application security testing (SAST/DAST) using tools such as CodeQL, Trivy, Dependency Check, SonarQube, and Burp Suite
+ Perform basic manual testing and validation of vulnerabilities in development and pre-production environments
+ Support secure code reviews under supervision, identifying potential security flaws in application logic or design
+ Collaborate with software developers to provide guidance on secure coding practices and vulnerability remediation
+ Triage vulnerability reports and escalate findings based on severity and impact
+ Assist in the integration of security testing tools into CI/CD pipelines and automated testing environments
+ Contribute to the development of test cases and security use cases based on threat modeling or abuse case analysis
+ Support documentation of findings, test results, and risk assessments in systems such as JIRA or ServiceNow
+ Help maintain dashboards and reporting for tracking vulnerability trends and remediation status
+ Stay current on emerging security vulnerabilities, exploits, and application security best practices
+ Work closely with the Senior Manager to continuously improve the testing processes and tool coverage
+ Participate in knowledge sharing and security training initiatives with development teams
The pay range for this position is $33.94 to $53.46 per hour.
FLEX opportunities offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.
Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD.
_Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law._
Marriott International is the world's largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. **Be** where you can do your best work, **begin** your purpose, **belong** to an amazing global team, and **become** the best version of you.
Senior Product Manager, Application Security Testing
Posted today
Job Viewed
Job Description
Join to apply for the Senior Product Manager, Application Security Testing role at Datadog
Senior Product Manager, Application Security Testing17 hours ago Be among the first 25 applicants
Join to apply for the Senior Product Manager, Application Security Testing role at Datadog
Get AI-powered advice on this job and more exclusive features.
At Datadog, we're on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. We operate at high scaletrillions of data points per dayallowing for seamless collaboration and problem-solving among Dev, Ops and Security teams globally for tens of thousands of companies. Our culture values pragmatism, honesty, and simplicity to solve hard problems the right way.
Datadogs Application Security Testing products, part of our Code Security suite, utilize both static (SAST) and runtime (IAST) scanning to detect critical vulnerabilities across the application lifecycle, from the developer IDE through CI/CD and into production environments.
As a Senior Product Manager for Application Security Testing, you will be working with a talented team of engineers and product designers to continue the evolution of one of our fastest growing new products. You will be the go-to person for our highly-motivated sales and marketing teams
At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them.
What Youll Do:
- You will be heavily customer-focused, conducting dozens of meetings per month with current and prospective users to discover their needs, validate new feature ideas, support key sales opportunities, and share details of the product vision and roadmap.
- Work closely with engineering and product design to define and deliver new product capabilities.
- Partner with marketing and cross functional teams including sales, customer success , technical support and your own engineering team, to define Go-To-Market plans and strategy for our Code Security products.
- Drive the product planning process each quarter to set objectives and key results and get buy-in from the Datadog executive team.
- You have 6+ years of experience as a Product Manager (ideally working on a developer or security-focused SaaS product)
- You have either worked as an engineer previously or possess a deep interest, understanding and knowledge in software development and/or security.
- You have excellent verbal and written communication skills and the willingness to present and defend your ideas to technical stakeholders, executives, and customers alike
- You are customer-focused with high quality standards for your products
- You are passionate to work in a high growth and impact environment to build new products and scaling existing ones
- Bonus: You are passionate about AI and machine learning technologies and like to work hands-on to understand their capabilities and limitations.
Benefits & Growth:
- New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
- Continuous professional development, product training, and career pathing
- Intra-departmental mentor and buddy program for in-house networking
- An inclusive company culture, ability to join our Community Guilds
- Access to Inclusion Talks, our Internal panel discussions
- Free, global Spring Health benefits for employees and dependents age 6+
- Competitive global benefits
Datadog offers a competitive salary and equity package, and may include variable compensation. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Datadog offers a wide range of best in class, comprehensive and inclusive employee benefits for this role including healthcare, dental, parental planning, and mental health benefits, a 401(k) plan and match, paid time off, fitness reimbursements, and a discounted employee stock purchase plan.
The reasonably estimated yearly salary for this role at Datadog is:
$187,000$40,000 USD
About Datadog:
Datadog (NASDAQ: DDOG) is a global SaaS business, delivering a rare combination of growth and profitability. We are on a mission to break down silos and solve complexity in the cloud age by enabling digital transformation, cloud migration, and infrastructure monitoring of our customers entire technology stacks. Built by engineers, for engineers, Datadog is used by organizations of all sizes across a wide range of industries. Together, we champion professional development, diversity of thought, innovation, and work excellence to empower continuous growth. Join the pack and become part of a collaborative, pragmatic, and thoughtful people-first community where we solve tough problems, take smart risks, and celebrate one another. Learn more about #DatadogLife on Instagram, LinkedIn, and Datadog Learning Center.
Equal Opportunity at Datadog:
Datadog is an Affirmative Action and Equal Opportunity Employer and is proud to offer equal employment opportunity to everyone regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, and more. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Here are our Candidate Legal Notices for your reference.
Your Privacy:
Any information you submit to Datadog as part of your application will be processed in accordance with Datadogs Applicant and Candidate Privacy Notice. Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Product Management and Marketing
- Industries Software Development
Referrals increase your chances of interviewing at Datadog by 2x
Sign in to set job alerts for Senior Product Manager roles.New York, NY 175,000.00- 270,000.00 6 days ago
New York, NY 65,000.00- 129,225.00 22 hours ago
Senior Product Manager, UX Research ToolingNew York, NY 183,000.00- 271,000.00 4 days ago
Product Management Manager, Tabletop & GiftNew York, NY 62,500.00- 100,000.00 1 week ago
Holmdel, NJ 145,000.00- 150,000.00 1 week ago
New York, NY 165,000.00- 288,750.00 4 days ago
Senior Product Manager, Client ExperienceNew York, NY 94,000.00- 129,250.00 4 days ago
New York, NY 144,000.00- 252,000.00 6 days ago
Principal Product Manager, Core ExperiencesNew York, NY 252,000.00- 280,000.00 1 week ago
Product Owner I - Digital and Technology Partners - Digital Experience - HybridNew York, NY 109,000.00- 163,695.00 4 days ago
New York, NY 200,000.00- 275,000.00 9 months ago
Senior Product Manager, Banking & PaymentsNew York, NY 232,500.00- 319,000.00 6 days ago
Lead Product Manager - Data Products & InsightsNew York, NY 180,000.00- 230,000.00 4 days ago
New York, NY 201,000.00- 240,000.00 2 weeks ago
New York City Metropolitan Area 55.00- 63.00 3 weeks ago
Senior Product Manager, AI Workflows (FinData)New York, NY 169,000.00- 219,000.00 3 days ago
New York, NY 110,000.00- 140,000.00 1 month ago
Senior Product Manager - AI Guest CommunicationsNew York, NY 160,000.00- 230,000.00 3 months ago
New York, NY 81,000.00- 147,000.00 1 week ago
Senior Product Manager, Personalization and User ExperiencesNew York, NY 149,000.00- 170,000.00 2 weeks ago
New York, NY 170,000.00- 215,000.00 1 week ago
Were unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSenior Security Engineer - Penetration Testing
Posted 23 days ago
Job Viewed
Job Description
Our company is extremely passionate about security and the benefit it brings to our customers. We are aiming to bring in a mutli-tasking leader to direct and influence the next stage in our success.
General Expectations:
- Develop security implementations and plans li>Implement Protections
- Test for Vulnerabilities
- Monitor for Security Breaches
- Direct experience with anti-virus software, intrusion detection, firewalls and content filtering
- Knowledge of risk assessment tools, technologies and methods
- Experience designing secure networks, systems and application architectures
- Knowledge of disaster recovery, computer forensic tools, technologies and methods
- Experience planning, researching and developing security policies, standards and procedures
Security Application Testing Engineer
Posted 4 days ago
Job Viewed
Job Description
Join to apply for the Security Application Testing Engineer role at New Era Technology .
1 week ago Be among the first 25 applicants
Join to apply for the Security Application Testing Engineer role at New Era Technology .
Get AI-powered advice on this job and more exclusive features.
Join New Era Technology, where People First is at the heart of everything we do. With a global team of over 4,500 professionals, we're committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.
At New Era, you'll join a team-oriented culture that prioritizes your personal and professional development. Work alongside industry-certified experts, access continuous training, and enjoy competitive benefits. Driven by values like Community, Integrity, Agility, and Commitment, we nurture our people to deliver exceptional customer service.
If you want to make an impact in a supportive, growth-oriented environment, New Era is the place for you. Apply today and help us shape the future of worktogether.
SummaryWe are seeking a Senior Security Test Engineer with expertise in IPv6 networking and security validation. This role involves setting up and managing an IPv6-only testing environment, performing security and functionality tests, troubleshooting issues, and documenting findings.
Primary Duties- Expertise in IPv6 networking and security validation is required.
- Set up and manage the IPv6-only testing environment.
- Perform tests to validate functionality and security, troubleshoot issues, and document findings.
- Collaborate with Customer teams to ensure product IPv6 compatibility.
- Address gaps affecting certification.
- Senior Consultant with 8-10+ years in Security Application Testing.
- Expertise in IPv6 networking and security validation is required.
- Deep knowledge of IPv6 protocols, addressing, and dual-stack setups.
- Proficiency with security testing tools like Burp Suite and OWASP ZAP.
- Experience with network traffic analysis tools such as Wireshark.
- Ability to configure and troubleshoot IPv6-only environments.
- Strong test automation skills for security applications.
- Experience with log analysis tools like ELK Stack or Splunk.
- Knowledge of test management tools such as Jira and TestRail.
- Ability to produce detailed technical documentation and test reports.
- Certified IPv6 Network Engineer (CNE6)
- Certified IPv6 Security Specialist
Pay Range: $120$125 USD, based on qualifications and experience.
#J-18808-LjbffrApplication Offensive Security Consultant | Application Security Testing
Posted 21 days ago
Job Viewed
Job Description
- s a member of Application Security team you will provide support in offensive security assessments on applications.
- Provide SME guidance to key projects.
- Perform security assessments and offer technical direction.
- Ensure security best practices in application development.
- Conduct offensive security testing on applications and APIs.
- Perform application threat hunting to assess risks.
- Execute manual security testing of applications.
- Document vulnerabilities in predefined report formats using manual methods and tools.
- Generate reports summarizing assessment findings for remediation.
- ct as a subject matter expert for application defense enhancements.
- Collaborate with Security Architects, Product Managers, and Risk Managers.
- Minimum 6 years of experience in web application security testing.
- Minimum 4 years of hands-on experience with Burp Suite and OWASP ZAP .
- bility to manually identify vulnerabilities in OWASP Top 10 without automated scanning.
- Understanding of MITRE Framework and adversarial methodologies.
- Bachelor's degree or equivalent experience.
- Offensive security or penetration testing certifications.
- Completion of penetration testing & red teaming courses.
- Passion for Capture the Flag (CTF) challenges and platforms like TryHackMe or HackTheBox .
- bility to multitask and work under pressure.
Application Penetration testers /Dynamic Application Security Testing (DAST)
Posted 21 days ago
Job Viewed
Job Description
San Francisco CA or New York City, NY or Charlotte NC or Irving TX or Chandler AZ or Minneapolis MN (Hybrid 3-5 days onsite)
12+ Months
Web cam Interview
$55-$60/Hr on W2
NOT:
- Manager mentioned he has read many resumes the past 2 weeks However many of the candidates submitted were not true application penetration testers.
- He saw many who would classify as a QA analyst by their job classification.
- He saw many others where they worked with third parties who did pen tests, but they never did tests themselves.
- He is also seeing a lot of people who run vulnerability scans, however this is not Dynamic Application Security Testing (DAST).
- In this contingent resource assignment, you may: Consult on or participate in moderately complex initiatives and deliverables within Information Security Engineering and contribute to large-scale planning related to Information Security Engineering deliverables.
- Review and analyze moderately complex Information Security Engineering challenges that require an in-depth evaluation of variable factors.
- Contribute to the resolution of moderately complex issues and consult with others to meet Information Security Engineering deliverables while leveraging solid understanding of the function policies procedures and compliance requirements.
- Collaborate with client personnel in Information Security Engineering.
- 4 years of Information Security Engineering experience or equivalent demonstrated through one or a combination of the following: work or consulting experience training military experience education.
The Senior Information Security Engineer will:
- Conduct Dynamic Application Security Testing (DAST) through manual testing and by using automated testing tools
- Review test results from tools
- Ensure that DAST tests are completed successfully
- Identify and remove any false positives from automated testing tool reports
- Triage & Disposition results and enforce a Bug Bar
- Verify/validate defect fixes
- Provide application security consulting SME Support to developers
- ssist developers with understanding of security defects and risk
- ssist in defining acceptable solution to fix defects
- Stay up to speed on 3rd party (inside and outside Wells Fargo) known security vulnerabilities
- Develop and review malicious use cases/threat models
- Maintain a broad understanding of security technologies and products
- 5 years of information security applications and systems experience
- 3 years of DAST Dynamic Application Security Testing experience
- 3 years of automated information security penetration tools experience
- Penetration testing certification such us GPEN GXPEN GWAPT or OSCP
Be The First To Know
About the latest Security testing Jobs in United States !
Principal Product Security Engineer, Penetration Testing - Minneapolis, MN

Posted 4 days ago
Job Viewed
Job Description
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
**A Day in the Life**
Act boldly. Compete to win. Move with speed and decisiveness. Foster belonging. Deliver results.the right way. That's the Medtronic Mindset - our cultural norms. Our brand is rooted in action, not just words. The Medtronic Mindset defines the expectations of our culture. Every person here plays a role in bringing it to life. We recognize your extraordinary potential to ensure future generations live better, healthier lives.
The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices.
The Penetration Testing team within the Product Security Office is responsible for providing attacker-like testing, product assessments, and other feedback on the security of devices for Medtronic's products to the distributed Operating Units across the organization.
The Principal Product Security Penetration Testing Engineer will execute complex testing to identify vulnerabilities in Medtronic products and assist with the identification of mitigation strategies. This testing will occur throughout a product's lifecycle for new product development and market-released products. This person will report to Enterprise Quality, members of this team will consult with product development and support organizations, scope assessments, conduct testing, summarize results, and report findings; all with a high degree of quality, autonomy, and speed.
This role requires on-site work at a Medtronic facility four days per week. Candidates must live within a reasonable commute to any Medtronic office, with a preference for those based near the Minneapolis, MN, area.
Responsibilities may include the following and other duties may be assigned.
+ Scope, conduct, and report results of product security penetration tests to key stakeholders
+ Contribute ideas to the team to help design test scenarios and improve penetration testing processes
+ Coach junior members on the team and review testing results to ensure accuracy and completeness
+ Rate the severity of vulnerabilities that are identified through testing
+ Stay up to date on current security knowledge
+ Employ a variety of test methods to perform comprehensive vulnerability assessment and penetration testing of products
+ Identify and leverage appropriate tools and techniques to accomplish testing
+ Coordinate with product development engineers to ensure understanding of findings
+ Document, communicate, and summarize the results of testing to relevant stakeholders, including formal test reports
+ Maintain awareness of existing and emerging security research and leverage that knowledge during internal testing activities (an "attacker-like" approach to testing)
+ Analyze, triage and recreate vulnerabilities submitted to Medtronic by 3rd party security researchers
+ Understand current regulations and utilize that knowledge to inform internal testing activities
+ Show creativity and innovation in all aspects of your responsibilities
+ Operate with a high level of independence
+ Contribute to Product Security Office Fiscal Year Initiatives and strategic plans
+ Support ad hoc Product Security Office campaigns and initiatives
+ Expected Travel: Up to 20%
**Must Have: Minimum Requirements:**
_To be considered for this role, please ensure the minimum requirements are evident on your resume._
+ Bachelors degree required
+ Minimum of 7 years of cybersecurity and/or secure software engineering experience
+ OR advanced degree with 5 years of cybersecurity and/or secure software engineering experience.
**Nice to Have:**
+ Experience in Product Security
+ Direct experience in penetration testing
+ Penetration Testing Certifications (e.g. CEH, OSCP, OSWA, GPEN, GMOB, Pentest+, etc.).
+ Other Information Security Certifications (e.g. Security+, CISSP, CISM, GSEC, etc.).
+ Experience assessing and testing the embedded security of regulated or safety critical devices.
+ Knowledge of the medical device industry.
+ Experience performing hardware and software penetration testing.
+ Experience working as an engineer or developer for embedded device hardware or firmware, mobile applications, web applications, or desktop applications.
+ Understanding of the security development process and product development process.
+ Ability to be creative to think "outside the box".
+ Experience facilitating working sessions.
+ Knowledge in risk management and assessment methodologies, security frameworks and relevant global regulations.
+ Strong capability to research and evaluate emerging technologies.
+ Demonstrated ability to be flexible and take a proactive approach to managing change.
+ Excellent written and verbal communication skills.
+ Experience working in a highly regulated industry and/or a formal quality system.
+ Occasional after-hours availability to accommodate different regional and global partners.
+ Strong in interpersonal communication and demonstrate a collaborative work style.
+ Comfortable working in an ambiguous environment.
+ Innovative thinker; ability to think outside of the current norms and processes
+ Independent self-starter
+ Strong communication and collaboration skills
**Physical Job Requirements**
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
**Benefits & Compensation**
**Medtronic offers a competitive Salary and flexible Benefits Package**
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$152,800.00 - $229,200.00
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans ( Medtronic**
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here ( .
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here ( a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
**We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.
**We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.
**This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will.
+ **Build** a better future, amplifying your impact on the causes that matter to you and the world
+ **Grow** a career reflective of your passion and abilities
+ **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning
These commitments set our team apart from the rest:
**Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.
**Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.
**Better outcomes for our world** . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.
**Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.
This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here ( .
For updates on job applications, please go to the candidate login page and sign in to check your application status.
If you need assistance completing your application please email
To request removal of your personal information from our systems please email
Security Engineer, AppSec Testing Automation and Insights
Posted 23 days ago
Job Viewed
Job Description
Description
Do you like working through abstract problems to implement creative solutions? Do you like to blend your day with both big and small issues? How does working across a variety of Amazon’s biggest teams sound?
In the Application Security Testing Automation and Insights team, our mission is to proactively secure application resources across all Amazon using deep research and scalable automation. We help our builder teams resolve issues before promoting code to production. We seek to automate difficult to identify patterns, and work with teams to make remediation fast and accurate. Our team knows few boundaries and is willing to go to any length to solve big issues.
As a member of our team, you will bring your curiosity to learn and attention to detail to execute strategies and tactics that drive security and efficiency across all areas. You will work in a collaborative team environment, operating autonomously and leading your own projects with some guidance under more tenured engineers. You will define guidance and remediation for our vast engineering community to implement. You will help raise the security bar across many of your favorite businesses. If you want to be apart of this fast paced, challenge driven team apply below. You will fearlessly drive Amazon’s security bar and high standards.
Key job responsibilities
• Develop, curate, and improve highly scalable application security rules to identify coding and configuration flaws
• Evaluate and recommend new security testing tools
• Deep dive code and research application frameworks to identify weaknesses and detection opportunities
• Leverage application system telemetry to extract insights and identify vulnerabilities
• Analyze and secure our applications during runtime
• Detect perimeter exposures
• Develop, enhance, and interpret security standards and guidance
• Demonstrate and promote security best practices, drive improvements of Amazon’s overall security architecture
About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
#JoinStoresAppSec
Basic Qualifications
-
3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
-
Bachelor's degree in computer science or equivalent
-
Knowledge of networking protocols such as HTTP, DNS and TCP/IP
Preferred Qualifications
-
2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
-
Experience with AWS products and services
-
Experience with programming languages such as Python, Java, C+Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.
Security Engineer, AppSec Testing Automation and Insights
Posted 23 days ago
Job Viewed
Job Description
Description
Do you like working through abstract problems to implement creative solutions? Do you like to blend your day with both big and small issues? How does working across a variety of Amazon’s biggest teams sound?
In the Application Security Testing Automation and Insights team, our mission is to proactively secure application resources across all Amazon using deep research and scalable automation. We help our builder teams resolve issues before promoting code to production. We seek to automate difficult to identify patterns, and work with teams to make remediation fast and accurate. Our team knows few boundaries and is willing to go to any length to solve big issues.
As a member of our team, you will bring your curiosity to learn and attention to detail to execute strategies and tactics that drive security and efficiency across all areas. You will work in a collaborative team environment, operating autonomously and leading your own projects with some guidance under more tenured engineers. You will define guidance and remediation for our vast engineering community to implement. You will help raise the security bar across many of your favorite businesses. If you want to be apart of this fast paced, challenge driven team apply below. You will fearlessly drive Amazon’s security bar and high standards.
Key job responsibilities
• Develop, curate, and improve highly scalable application security rules to identify coding and configuration flaws
• Evaluate and recommend new security testing tools
• Deep dive code and research application frameworks to identify weaknesses and detection opportunities
• Leverage application system telemetry to extract insights and identify vulnerabilities
• Analyze and secure our applications during runtime
• Detect perimeter exposures
• Develop, enhance, and interpret security standards and guidance
• Demonstrate and promote security best practices, drive improvements of Amazon’s overall security architecture
About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
#JoinStoresAppSec
Basic Qualifications
-
3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
-
Bachelor's degree in computer science or equivalent
-
Knowledge of networking protocols such as HTTP, DNS and TCP/IP
Preferred Qualifications
-
2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
-
Experience with AWS products and services
-
Experience with programming languages such as Python, Java, C+Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.