4,832 Security Testing jobs in the United States

FLEX Application Security Testing Analyst

20814 Bethesda, Maryland Marriott

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

**Additional Information**
**Job Number**
**Job Category** Information Technology
**Location** Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States, 20814VIEW ON MAP ( Full Time
**Located Remotely?** N
**Position Type** Management
This is a temporary position.
The Application Security Testing Analyst will support the assessment and improvement of Web, API, Mobile application security through hands-on security testing and code analysis. The ideal candidate will have a solid foundation in secure coding practices, vulnerability detection, and testing techniques such as SAST, DAST, and manual testing. This role is designed to offer practical experience in application security testing, with opportunities to work directly with development teams, security tools, and automation in real-world environments.
**CANDIDATE PROFILE**
**Education and Experience**
**Required:**
+ Bachelor's degree in Cybersecurity, Computer Science or related field or equivalent experience/certification
+ 2+ years of information technology or application development experience
+ Strong understanding of programming concepts (e.g., loops, data types, logic, input/output)
+ Basic experience or familiarity with application security testing tools (e.g., Burp Suite, OWASP ZAP, Fortify, Veracode)
+ Understanding of the OWASP Top 10 and common application vulnerabilities (e.g., XSS, SQLi, CSRF)
+ Basic knowledge of vulnerability triage and remediation processes
+ Familiarity with version control (e.g., Git), CI/CD concepts, and the SDLC
+ Proficiency in Microsoft Word, PowerPoint, and Excel
+ Excellent communication skills
**Preferred:**
+ Master's degree in Cybersecurity, Computer Science, or related field or equivalent experience/certification
+ Security certifications (e.g., GWAPT, OSCP, CEH, Security+, or CySA+)
+ 2+ years of experience in an application security, QA, or software testing role
+ Experience performing web application penetration testing or source code review
+ Exposure to secure SDLC practices and integrating testing into CI/CD pipelines
+ Understanding of risk scoring frameworks (e.g., CVSS) and security ticketing workflows
+ Familiarity with compliance standards such as PCI-DSS, NIST 800-53, or ISO 27001
**CORE WORK ACTIVITIES**
**Application Security Risk Management & Tracking**
+ Application Security Testing & Risk Analysis
+ Assist with static and dynamic application security testing (SAST/DAST) using tools such as CodeQL, Trivy, Dependency Check, SonarQube, and Burp Suite
+ Perform basic manual testing and validation of vulnerabilities in development and pre-production environments
+ Support secure code reviews under supervision, identifying potential security flaws in application logic or design
+ Collaborate with software developers to provide guidance on secure coding practices and vulnerability remediation
+ Triage vulnerability reports and escalate findings based on severity and impact
+ Assist in the integration of security testing tools into CI/CD pipelines and automated testing environments
+ Contribute to the development of test cases and security use cases based on threat modeling or abuse case analysis
+ Support documentation of findings, test results, and risk assessments in systems such as JIRA or ServiceNow
+ Help maintain dashboards and reporting for tracking vulnerability trends and remediation status
+ Stay current on emerging security vulnerabilities, exploits, and application security best practices
+ Work closely with the Senior Manager to continuously improve the testing processes and tool coverage
+ Participate in knowledge sharing and security training initiatives with development teams
The pay range for this position is $33.94 to $53.46 per hour.
FLEX opportunities offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.
Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD.
_Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law._
Marriott International is the world's largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. **Be** where you can do your best work, **begin** your purpose, **belong** to an amazing global team, and **become** the best version of you.
View Now

Principal Product Security Engineer, Penetration Testing - Minneapolis, MN

55112 Mounds View, Minnesota Medtronic

Posted 8 days ago

Job Viewed

Tap Again To Close

Job Description

We anticipate the application window for this opening will close on - 13 Oct 2025
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
**A Day in the Life**
Act boldly. Compete to win. Move with speed and decisiveness. Foster belonging. Deliver results.the right way. That's the Medtronic Mindset - our cultural norms. Our brand is rooted in action, not just words. The Medtronic Mindset defines the expectations of our culture. Every person here plays a role in bringing it to life. We recognize your extraordinary potential to ensure future generations live better, healthier lives.
The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices.
The Penetration Testing team within the Product Security Office is responsible for providing attacker-like testing, product assessments, and other feedback on the security of devices for Medtronic's products to the distributed Operating Units across the organization.
The Principal Product Security Penetration Testing Engineer will execute complex testing to identify vulnerabilities in Medtronic products and assist with the identification of mitigation strategies. This testing will occur throughout a product's lifecycle for new product development and market-released products. This person will report to Enterprise Quality, members of this team will consult with product development and support organizations, scope assessments, conduct testing, summarize results, and report findings; all with a high degree of quality, autonomy, and speed.
This role requires on-site work at a Medtronic facility four days per week. Candidates must live within a reasonable commute to any US Medtronic office, with a preference for those based near the Minneapolis, MN, area.
Responsibilities may include the following and other duties may be assigned.
+ Scope, conduct, and report results of product security penetration tests to key stakeholders
+ Contribute ideas to the team to help design test scenarios and improve penetration testing processes
+ Coach junior members on the team and review testing results to ensure accuracy and completeness
+ Rate the severity of vulnerabilities that are identified through testing
+ Stay up to date on current security knowledge
+ Employ a variety of test methods to perform comprehensive vulnerability assessment and penetration testing of products
+ Identify and leverage appropriate tools and techniques to accomplish testing
+ Coordinate with product development engineers to ensure understanding of findings
+ Document, communicate, and summarize the results of testing to relevant stakeholders, including formal test reports
+ Maintain awareness of existing and emerging security research and leverage that knowledge during internal testing activities (an "attacker-like" approach to testing)
+ Analyze, triage and recreate vulnerabilities submitted to Medtronic by 3rd party security researchers
+ Understand current regulations and utilize that knowledge to inform internal testing activities
+ Show creativity and innovation in all aspects of your responsibilities
+ Operate with a high level of independence
+ Contribute to Product Security Office Fiscal Year Initiatives and strategic plans
+ Support ad hoc Product Security Office campaigns and initiatives
+ Expected Travel: Up to 20%
**Must Have: Minimum Requirements:**
_To be considered for this role, please ensure the minimum requirements are evident on your resume._
+ Bachelors degree required
+ Minimum of 7 years of cybersecurity and/or secure software engineering experience
+ OR advanced degree with 5 years of cybersecurity and/or secure software engineering experience.
**Nice to Have:**
+ Experience in Product Security
+ Direct experience in penetration testing
+ Penetration Testing Certifications (e.g. CEH, OSCP, OSWA, GPEN, GMOB, Pentest+, etc.).
+ Other Information Security Certifications (e.g. Security+, CISSP, CISM, GSEC, etc.).
+ Experience assessing and testing the embedded security of regulated or safety critical devices.
+ Knowledge of the medical device industry.
+ Experience performing hardware and software penetration testing.
+ Experience working as an engineer or developer for embedded device hardware or firmware, mobile applications, web applications, or desktop applications.
+ Understanding of the security development process and product development process.
+ Ability to be creative to think "outside the box".
+ Experience facilitating working sessions.
+ Knowledge in risk management and assessment methodologies, security frameworks and relevant global regulations.
+ Strong capability to research and evaluate emerging technologies.
+ Demonstrated ability to be flexible and take a proactive approach to managing change.
+ Excellent written and verbal communication skills.
+ Experience working in a highly regulated industry and/or a formal quality system.
+ Occasional after-hours availability to accommodate different regional and global partners.
+ Strong in interpersonal communication and demonstrate a collaborative work style.
+ Comfortable working in an ambiguous environment.
+ Innovative thinker; ability to think outside of the current norms and processes
+ Independent self-starter
+ Strong communication and collaboration skills
#LI-MDT
**Physical Job Requirements**
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. 
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
**Benefits & Compensation**
**Medtronic offers a competitive Salary and flexible Benefits Package**
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$152,800.00 - $229,200.00
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans ( Medtronic**
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here ( .
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here ( a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
**We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.
**We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.
**This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will.
+ **Build** a better future, amplifying your impact on the causes that matter to you and the world
+ **Grow** a career reflective of your passion and abilities
+ **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning
These commitments set our team apart from the rest:
**Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.
**Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.
**Better outcomes for our world** . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.
**Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.
This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here ( .
For updates on job applications, please go to the candidate login page and sign in to check your application status.
If you need assistance completing your application please email
To request removal of your personal information from our systems please email
View Now

Penetration Testing Security Specialist Lead (CSTA)

43224 Columbus, Ohio American Electric Power

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Posting End Date

Please note the job posting will close on the day before the posting end date.

Job Summary

Responsible for large-scale security assignments providing direction to other team members. Responsible for gathering, investigating, and analyzing very complex security requirements, processes, and incidents. Leads analysis of security controls assessments (internal and third party) through application security testing, penetration testing or other means to ensure controls effectiveness. Leads the identification and documentation of potential mitigations /remediations and ensures report creation of findings with identified risk response. Responsible for the conceptual design of implementation strategies on assigned security projects/activities. Leads advanced level implementation, support, and/or usage of technical solutions. Leads others in advanced problem solving, decision-making, and functional area knowledge. Mentors and provides functional/technical work direction to team.

Job Description

What You'll Do:

  • Lead moderate to highly complex technical security assessments across diverse technology, business systems, and critical infrastructure.

  • Document complex technical findings and communicate them effectively in both written and verbal forms to key stakeholders, including Senior and Executive Leadership.

  • Provide actionable, technically sound recommendations to facilitate effective risk treatment of identified findings.

  • Advise Security Leadership and offer deep technical subject matter expertise for large-scale security and technology initiatives.

  • Fulfill technical functions in this role, including:

  • Application Security Lead

  • Penetration Tester / "Red Team" Lead

  • Security Tool Administrator Lead

What We're Looking For:

Security Specialist Lead (SG9):

Education: Bachelor's degree in computer science, information systems, business or related field of study; Or Associate's degree in computer science or related field of study with 2 years of relevant work experience; Or High school diploma/GED with 4 years of relevant work experience.

Experience: In addition to any experience required above, 10 years of relevant work experience is required.

Nice-to-have:

  • Three or more years of technical Penetration Testing / Application Security specific experience, or commensurate related experience.

  • Demonstrated expertise in penetration testing methodologies and the ability to apply these methodologies in varied technology environments, both independently and as a team leader.

  • Demonstrable technical experience in one or more of the following disciplines:

  • Network / Critical Infrastructure Penetration Testing

  • Web Application / Web Service Penetration Testing

  • Mobile / IoT Penetration Testing

  • Software / Malware Reverse Engineering

  • Hardware / Firmware Reverse Engineering

  • Application Development and Testing

  • Cloud / Container Security

  • Red Teaming / Threat Emulation

  • Technical security certifications are beneficial (e.g., OSCP, OSWE, OSCE, LPT, GPEN, GWAPT, GMOB, GXPN, GAWN, GCPN, GCE, CISSP).

  • Some travel or overtime may be required.

What you’ll get:

Security Specialist Lead (SG9): $112,869.00-$46,730.50

In addition to a competitive compensation, AEP offers a unique comprehensive benefits package that aims to support and enhance the overall well-being of our employees.

Where Putting the Customer First Powers Everything We Do

At AEP, we’re more than just an energy company — we’re a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you're passionate about making a meaningful impact and being part of a forward-thinking organization, this is the company for you!

#AEPCareers

#LI-ONSITE

Compensation Data

Compensation Grade:

SP20-009

Compensation Range:

$112, 730.50 USD

The Physical Demand Level for this job is: S – Sedentary Work: Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.

Hear about it first! Get job alerts by email. Log in to your Candidate Home Account today! If you don't have an account, you can create one.

It is hereby reaffirmed that it is the policy of American Electric Power (AEP) to provide Equal Employment Opportunity in all respects of the employer-employee relationship including recruiting, hiring, upgrading and promotion, conditions and privileges of employment, company sponsored training programs, educational assistance, social and recreational programs, compensation, benefits, transfers, discipline, layoffs and termination of employment to all employees and applicants without discrimination because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, veteran or military status, disability, genetic information, or any other basis prohibited by applicable law. When required by law, we might record certain information or applicants for employment may be invited to voluntarily disclose protected characteristics.

View Now

Penetration Testing Security Specialist Lead (CSTA)

43201 Columbus, Ohio American Electric Power

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

**Job Posting End Date**

Please note the job posting will close on the day before the posting end date.
**Job Summary**
Responsible for large-scale security assignments providing direction to other team members. Responsible for gathering, investigating, and analyzing very complex security requirements, processes, and incidents. Leads analysis of security controls assessments (internal and third party) through application security testing, penetration testing or other means to ensure controls effectiveness. Leads the identification and documentation of potential mitigations /remediations and ensures report creation of findings with identified risk response. Responsible for the conceptual design of implementation strategies on assigned security projects/activities. Leads advanced level implementation, support, and/or usage of technical solutions. Leads others in advanced problem solving, decision-making, and functional area knowledge. Mentors and provides functional/technical work direction to team.
**Job Description**
**What You'll Do:**
+ Lead moderate to highly complex technical security assessments across diverse technology, business systems, and critical infrastructure.
+ Document complex technical findings and communicate them effectively in both written and verbal forms to key stakeholders, including Senior and Executive Leadership.
+ Provide actionable, technically sound recommendations to facilitate effective risk treatment of identified findings.
+ Advise Security Leadership and offer deep technical subject matter expertise for large-scale security and technology initiatives.
+ Fulfill technical functions in this role, including:
+ Application Security Lead
+ Penetration Tester / "Red Team" Lead
+ Security Tool Administrator Lead
**What We're Looking For:**
**Security Specialist Lead (SG9):**
**Education:** Bachelor's degree in computer science, information systems, business or related field of study; Or Associate's degree in computer science or related field of study with 2 years of relevant work experience; Or High school diploma/GED with 4 years of relevant work experience.
**Experience:** In addition to any experience required above, 10 years of relevant work experience is required.
**Nice-to-have:**
+ Three or more years of technical Penetration Testing / Application Security specific experience, or commensurate related experience.
+ Demonstrated expertise in penetration testing methodologies and the ability to apply these methodologies in varied technology environments, both independently and as a team leader.
+ Demonstrable technical experience in one or more of the following disciplines:
+ Network / Critical Infrastructure Penetration Testing
+ Web Application / Web Service Penetration Testing
+ Mobile / IoT Penetration Testing
+ Software / Malware Reverse Engineering
+ Hardware / Firmware Reverse Engineering
+ Application Development and Testing
+ Cloud / Container Security
+ Red Teaming / Threat Emulation
+ Technical security certifications are beneficial (e.g., OSCP, OSWE, OSCE, LPT, GPEN, GWAPT, GMOB, GXPN, GAWN, GCPN, GCE, CISSP).
+ Some travel or overtime may be required.
**What you'll get:**
**Security Specialist Lead (SG9): $112,869.00-$46,730.50**
In addition to a competitive compensation, AEP offers a unique comprehensive benefits package that aims to support and enhance the overall well-being of our employees.
Where Putting the Customer First Powers Everything We Do
At AEP, we're more than just an energy company - we're a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you're passionate about making a meaningful impact and being part of a forward-thinking organization, this is the company for you!
#AEPCareers
#LI-ONSITE
**Compensation Data**
**Compensation Grade:**
SP20-009
**Compensation Range:**
112, ,730.50 USD
The Physical Demand Level for this job is: S - Sedentary Work: Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
**Hear about it first!** Get job alerts by email. Log in to your Candidate Home Account today! If you don't have an account, you can create one.
It is hereby reaffirmed that it is the policy of American Electric Power (AEP) to provide Equal Employment Opportunity in all respects of the employer-employee relationship including recruiting, hiring, upgrading and promotion, conditions and privileges of employment, company sponsored training programs, educational assistance, social and recreational programs, compensation, benefits, transfers, discipline, layoffs and termination of employment to all employees and applicants without discrimination because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, veteran or military status, disability, genetic information, or any other basis prohibited by applicable law. When required by law, we might record certain information or applicants for employment may be invited to voluntarily disclose protected characteristics.
View Now

Senior Information Security Analyst, Penetration Testing

23451 Virginia Beach, Virginia $120000 Annually WhatJobs

Posted 7 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a leading organization in Virginia Beach, Virginia, US , is seeking a highly skilled Senior Information Security Analyst with a specialization in Penetration Testing. This role is essential for identifying and mitigating security vulnerabilities across our IT infrastructure and applications. You will be responsible for planning, executing, and reporting on comprehensive penetration tests, vulnerability assessments, and security audits. The ideal candidate will possess a deep understanding of common attack vectors, exploit techniques, and security best practices. Responsibilities include simulating cyber-attacks to uncover weaknesses, recommending remediation strategies, and working closely with development and operations teams to implement security enhancements. You will also contribute to the development and refinement of security policies and procedures. The ability to communicate technical findings clearly and effectively to both technical and non-technical audiences is crucial. A strong knowledge of network protocols, operating systems, web application security, and cloud security is required. Relevant security certifications such as CISSP, CEH, OSCP, or equivalent are highly desirable. A Bachelor's degree in Computer Science, Information Security, or a related field, coupled with a minimum of 7 years of experience in information security, with a significant focus on offensive security and penetration testing, is required. This position offers a hybrid work model, providing a blend of on-site collaboration and remote flexibility, enabling you to contribute to a robust security posture within a growing industry.
Apply Now

Senior Information Security Analyst - Penetration Testing

27601 Whispering Pines, North Carolina $115000 Annually WhatJobs

Posted 7 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly skilled and motivated Senior Information Security Analyst with a specialization in Penetration Testing to join their growing security team in **Raleigh, North Carolina, US**. This role is crucial in identifying vulnerabilities and weaknesses within the organization's IT infrastructure, applications, and networks to proactively enhance security posture. The ideal candidate will possess deep technical expertise in offensive security techniques, penetration testing methodologies, and vulnerability assessment tools. You will be responsible for planning and executing comprehensive penetration tests, red team exercises, and security assessments. This position requires a strong understanding of network protocols, operating systems, web application security, and cloud security. You will document findings, provide actionable recommendations for remediation, and work closely with IT and development teams to implement security improvements. The Senior Information Security Analyst will also contribute to developing security policies, procedures, and best practices. A proactive, curious, and analytical mindset is essential, along with excellent reporting and communication skills to articulate complex technical issues to both technical and non-technical audiences.

Key Responsibilities:
  • Plan, scope, and execute penetration tests against internal and external networks, applications, and cloud environments.
  • Conduct vulnerability assessments and identify security weaknesses using a variety of tools and techniques.
  • Perform red team exercises to simulate real-world attack scenarios and test incident response capabilities.
  • Analyze security vulnerabilities and provide detailed, actionable remediation recommendations.
  • Document penetration test findings clearly and concisely in comprehensive reports.
  • Present test results and recommendations to technical teams and management.
  • Assist in the development and maintenance of security policies, standards, and procedures.
  • Stay up-to-date with the latest security threats, vulnerabilities, and attack vectors.
  • Collaborate with IT and development teams to implement security controls and address identified risks.
  • Participate in security architecture reviews and provide input on secure design principles.
  • Develop and maintain security testing tools and scripts.
  • Contribute to security awareness training for employees.
  • Research and evaluate new security technologies and methodologies.
  • Act as a subject matter expert in offensive security and penetration testing.

Qualifications:
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • 5+ years of experience in information security, with a significant focus on penetration testing and offensive security.
  • Proven experience conducting network, web application, and mobile application penetration tests.
  • Proficiency with penetration testing tools such as Metasploit, Burp Suite, Nmap, Nessus, and Wireshark.
  • Strong understanding of TCP/IP, networking protocols, operating systems (Windows, Linux), and common attack vectors.
  • Experience with cloud security concepts and testing in AWS, Azure, or GCP environments.
  • Excellent analytical and problem-solving skills.
  • Strong written and verbal communication skills, with the ability to produce detailed technical reports.
  • Relevant certifications such as OSCP, CEH, CISSP, or GIAC are highly desirable.
  • Ability to work independently and as part of a team.
  • Ethical mindset and strong understanding of security principles.
  • Experience with scripting languages (e.g., Python, PowerShell) is a plus.
Apply Now

Senior Information Security Analyst - Penetration Testing

84057 Orem, Utah $125000 Annually WhatJobs

Posted 7 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a rapidly expanding technology firm, is seeking a highly skilled Senior Information Security Analyst specializing in Penetration Testing. This fully remote role is integral to safeguarding our digital assets and identifying vulnerabilities before malicious actors can exploit them. The ideal candidate possesses a deep understanding of offensive security techniques, network protocols, and common attack vectors. You will be responsible for conducting comprehensive penetration tests, vulnerability assessments, and security audits across our infrastructure, applications, and cloud environments.

Key Responsibilities:
  • Perform comprehensive network, web application, and mobile application penetration tests.
  • Conduct vulnerability assessments and penetration testing using various tools and methodologies.
  • Identify, analyze, and report on security vulnerabilities and recommend remediation strategies.
  • Develop and maintain security testing tools and scripts.
  • Simulate real-world attacks to evaluate the effectiveness of existing security controls.
  • Document findings in clear, concise, and actionable reports for both technical and non-technical audiences.
  • Collaborate with development and operations teams to address identified security issues.
  • Stay current with the latest security threats, vulnerabilities, and penetration testing techniques.
  • Participate in security awareness training and contribute to security best practices.
  • Maintain certifications relevant to information security and penetration testing.
  • Assist in the development and implementation of security policies and procedures.
  • Contribute to the continuous improvement of the information security program.

This is a remote-first position, offering the flexibility to work from anywhere within the United States. You will utilize advanced communication and collaboration tools to engage with our global security team. The successful candidate will demonstrate exceptional analytical and problem-solving skills, a strong ethical compass, and a passion for cybersecurity. Relevant certifications such as OSCP, CISSP, or CEH are highly desirable. While the company has a presence in **Provo, Utah, US**, this role does not require physical office attendance. We are looking for dedicated security professionals committed to protecting our organization from cyber threats.
Apply Now
Be The First To Know

About the latest Security testing Jobs in United States !

Security Operations Engineer (Threat Detection & Penetration Testing)

Bask Health

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

remote

You will be leveraging your security operations experience to analyze and respond to security notifications, events, and inquiries. You will be performing initial triage of potential security incidents through log and data analysis to determine whether or not activity is a substantiated or valid threat, assessing severity and potential impact, taking pre-approved remediation measures to contain a threat, and escalating findings to investigators for further review and analysis. You will use your knowledge of cyber threats and the results of your analysis to coordinate with partner teams to improve threat detection through tuning and creation of new use cases, to improve capabilities through enriching existing data and creation of new data feeds, and to improve triage accuracy, consistency and timeliness through automation. This role plays a critical part in threat detection and response, ultimately reducing the likelihood of security breaches and protecting sensitive company information.

  • Analyze and investigate activity on company devices that could represent a security threat
  • Work cross-functionally with the Security teams to develop solutions for analyzing security events at scale and protecting Bask networks, systems, and data
  • Interpret disparate data sources to report on trends and support investigative requests
  • Collect requirements for enhancements to detection models and response systems
  • Leverage existing systems and data to perform analyses and promote process improvements 
  • Provide actionable insights to help identify, prevent, detect, and respond to anomalous or potentially malicious user activity
  • Collaborate effectively with teammates, lead projects, mentor others, and develop and champion quality operational standards across the team
  • Provide expert technical guidance on threat detection and penetration testing methodologies.
  • Drive the organizational security vision by prioritizing and overseeing the execution of projects aligned with our security roadmap.
  • Collaborate cross-functionally with security engineering teams to enhance detection systems, implement countermeasures, and ensure comprehensive protection of Stripe's networks, systems, and data.
  • Develop, document, and implement strategies, playbooks, and capabilities to advance our threat detection and penetration testing functions.
  • Continuously improve security processes by integrating feedback from penetration tests and threat detection activities into our security architecture.
  • Coach and mentor individual contributors, championing a culture of learning and excellence within the team.

Requirements

  • 5+ years experience in information technology or cyber security roles including security operations/incident response
  • 2+ years experience analyzing large data sets to solve problems and/or manage projects related to security event triage and/or workplace investigations
  • B.S. or M.S. in Cyber Security and Information Assurance, Data Analytics, Computer Science or related field, or equivalent experience
  • Working knowledge of SQL 
  • Basic knowledge of scripting or programming in Javascript, Typescript, Python, Kali Linux, and other programming languages
  • Proven experience with log querying and analysis (e.g. first or third party applications, system / data access, event logs), digital forensics, or incident response using one or more industry standard SIEM Platforms (Splunk, Sentinel, Chronicle, Elastic, etc.)
  • Proficiency using analytical methods to inform detection systems or guide strategic response
  • Strong cross-functional collaboration and written/verbal communication skills 
  • Ability to think creatively and holistically about identifying and reducing risk in a complex environment
  • High level of judgment, objectivity, and discretion 
Preferred qualifications
  • Prior experience working with high volume data in a security operations environment
  • Experience with data processing and analysis tools (e.g. Jupyter Notebooks, Databricks)
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors
  • Ability to leverage threat intelligence and/or hunting concepts in an enterprise environment
  • Experience in one or more of the following areas: user and entity behavior analytics (UEBA), SOAR/security automation, security information event management (SIEM), data loss prevention (DLP), Information Security, or Data Privacy
  • One or more security certifications through a recognized industry provider: GIAC, ISACA, ISC2, OffSec, CompTIA, etc.

Benefits

Fully Remote Position

View Now

Security Engineer

99811 Juneau, Alaska SCRAM Systems

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Job Summary:
The Security Engineer will focus on security concerns for the development, implementation, operations, and ongoing analysis of SCRAM Systems security and operational infrastructure. The ideal candidate will have a deep understanding of security topics, as well as in-depth knowledge of core infrastructure technologies. The engineer will be responsible for all the security aspects related to our physical and cloud infrastructure as well as the implementation and maturation of our security initiatives. They will work closely with all of SCRAM Systems' teams to ensure information systems are protected throughout the organization. The ideal candidate should have thorough engineering experience in security operational domains.
Join us in our mission to make a meaningful impact in the criminal justice field and help build a safer society. As a Security Engineer, you will be at the forefront of fortifying our infrastructure against evolving security threats and ensuring the confidentiality, integrity, and availability of our critical systems. Extensive analytical, technical, and administrative capability combined with passion for security is what we are looking for.
Duties/Responsibilities:
Security Strategy and Architecture:
· Work closely with the CISO to develop and maintain a comprehensive security strategy that aligns with organizational goals and risk tolerance.
· Review and implement security architecture for both Cloud and on-premises environments.
· Conduct security assessments to identify vulnerabilities and propose remediation measures.
Threat Detection and Incident Response:
· Implement advanced security monitoring and threat detection solutions to promptly identify security incidents.
· Lead incident response efforts, investigating and mitigating security breaches and cyber-attacks.
· Develop and maintain incident response plans and conduct periodic drills for the security team.
· Maintain rules on an Elastic stack SIEM to ensure threats are logged and real time notifications of threats are sent to appropriate parties.
· Maintain and mature our Threat and Vulnerability Management process.
Cloud Security:
· Establish and enforce security controls specific to a major cloud provider (i.e., Azure), ensuring data protection and compliance.
· Monitor and analyze cloud security logs and reports, taking proactive measures to address potential risks.
Infrastructure Security:
· Harden and secure Windows and Linux-based VMs in both cloud and on-premises environments.
· Implement security measures for Kubernetes clusters and containerized applications.
· Regularly audit infrastructure security and manage patching and updates.
Identity and Access Management (IAM):
· Design and maintain IAM solutions to control access privileges and permissions.
· Oversee access control mechanisms and ensure adherence to the principle of least privilege.
Security Compliance Auditing:
· Collaborate with internal teams to ensure compliance with relevant security standards, regulations, and policies related to the criminal justice domain.
· Conduct security audits, vulnerability assessments, and penetration testing as needed.
Security Awareness and Training:
· Conduct security training sessions for technical teams to promote a security-conscious culture.
· Stay up to date with the latest security trends, vulnerabilities, and best practices.
#LI-PROMOTE
Skills/Abilities:
· Proven experience as a Security Engineer in a data sensitive industry.
· In-depth knowledge of Cloud security, including IAM, VNet, Security Center (specific Azure Policies is a plus).
· Experience securing Windows and Linux-based VMs (proficiency in Kubernetes is a plus).
· Familiarity with security compliance frameworks such as NIST, ISO 27001, and CJIS.
· Hands-on experience with security tools and technologies, such as SIEM, TVM, IDS/IPS, and firewalls.
· Excellent problem-solving skills and the ability to think strategically about security issues.
· Effective communication and leadership skills, with the ability to collaborate across teams.
· High level of analytical and problem-solving abilities.
Education and Experience:
· Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience).
· Security and Industry certifications are a plus
· Azure experience is not required but is a plus.
Physical Requirements (With or without reasonable accommodation):
· Sitting: Over 70 %
*** All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
View Now

Security Engineer

99811 Juneau, Alaska Meta

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

**Summary:**
Cross-Meta Security's mission is to protect the company, our community, and their data while empowering safe innovation. To achieve this, we are building a small team of Senior Individual Contributors (ICs) who can solve security-related technical problems across the company in collaboration with various Meta product groups and pillars.
**Required Skills:**
Security Engineer Responsibilities:
1. Lead cross-organizational technical teams to solve challenging cross-domain security problems.
2. Bring together engineering teams that work in adjacent areas to build shared context and tackle bigger problems than they can solve individually.
3. Operate with ownership and accountability for one or more security risks at Meta and drive and influence people to do the right things to comprehensively address those risks while enabling the company to move fast.
4. Disambiguate and decompose problems and solutions and create clarity for others.
5. Provide technical guidance and collaborate with cross-functional partners to define projects goals and milestones.
6. Bolster engineering excellence in everything you do.
**Minimum Qualifications:**
Minimum Qualifications:
7. B.S. Computer Science or related field
8. 15+ years of experience managing security risk and navigating the tradeoff between security and friction in a large organization
9. 15+ years of experience in driving large cross-company engineering and Security initiatives
10. Experience with system design, threat modeling and risk assessment
11. Experience building engineered controls and guardrails to manage risks
12. Application of security principles such as least privilege, defense in depth, segmentation
13. Knowledge of current threat tactics, techniques, and procedures
14. Experience in distributed systems, access control, encryption, intrusion detection
15. Effective communication that creates clarity and simplicity for others
**Public Compensation:**
$264,000/year to $342,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at
View Now
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Testing Jobs