9,811 Security Testing jobs in the United States

Operations, Security Testing & Reporting Lead

78703 Austin, Texas 3M

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description

**Job Description:**
Operations Lead, Cyber Defense Data and Application Security
**Collaborate with Innovative 3Mers Around the World**
Choosing where to start and grow your career has a major impact on your professional and personal life, so it's equally important you know that the company that you choose to work at, and its leaders, will support and guide you. With a wide variety of people, global locations, technologies and products, 3M is a place where you can collaborate with other curious, creative 3Mers.
**This position provides an opportunity to transition from other private, public, government or military experience to a 3M career.**
**The Impact You Will Make in this Role**
As the Operations & Reporting Lead in the Cyber Defense team at our global manufacturing company, you will oversee financial and operational reporting, data governance, budget planning, resource allocation, and the management of our application security testing program. You'll partner closely with Finance, IT Security, Engineering, and Business Unit leaders to ensure data integrity, cost-effective operations, and robust security validation of critical applications.
Key Responsibilities:
+ Develop, maintain, and distribute monthly/quarterly operational and financial dashboards to senior leadership
+ Design ad-hoc reports and analyses to support business decision-making
+ Ensure accuracy and timeliness of KPI tracking (production throughput, quality metrics, security testing outcomes)
+ Align with 3M data standards, taxonomies, and data quality processes
+ Develop a Cyber Defense data strategy to support management and operational decision making and reporting
+ Manage Cyber Defense data quality, support corrective actions as necessary, and implement improvements
+ Own the annual operating and capital budget for reporting, data management, and security testing activities
+ Track actuals vs. budget; analyze variances and present recommendations for cost optimization
+ Partner with Finance to forecast resource and tool investments for the coming fiscal year
+ Plan headcount, contractors, and vendor engagements to meet operational and testing needs
+ Conduct quarterly capacity reviews and adjust resourcing plans to align with project pipelines
+ Mentor and develop a team of analysts, data stewards, and security-testing coordinators
+ Evolve the current application security testing program
+ Manage the pipeline of static, dynamic, and interactive application-security tests (SAST, DAST, IAST)
+ Build and maintain relationships with third-party security testing vendors and ensure SLA adherence
**Your Skills and Expertise**
To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:
+ Bachelor's degree in Business Administration, Information Systems, Finance, or Computer Science (completed and verified prior to start)
+ Five (5) years of operations or project management experience in a manufacturing or highly regulated industry in a private, public, government or military environment
Additional qualifications that could help you succeed even further in this role include:
+ Master's degree (MBA or MS in Information Systems)
+ Experience in global rollouts and cross-cultural team leadership
+ Certifications: PMP, CISSP, CISA, CISM, or Security+ Proven expertise in financial reporting, budget management, and data governance frameworks
+ Understanding of application security testing methodologies and tools
+ Proficiency with BI tools (e.g., Power BI, Tableau)
+ Excellent leadership, communication, and stakeholder management skills
**Work location: On site in** **Austin TX**
**Travel:** **May include up to 10** **% domestic and international**
**Relocation Assistance:** **Is Authorized**
**Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).**
**Supporting Your Well-being**
3M offers many programs to help you live your best life - both physically and financially. To ensure competitive pay and benefits, 3M regularly benchmarks with other companies that are comparable in size and scope.
**Chat with Max**
For assistance with searching through our current job openings or for more information about all things 3M, visit Max, our virtual recruiting assistant on 3M.com/careers.
Applicable to US Applicants Only:The expected compensation range for this position is $188,251 - $230,084, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate's relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: Faith Posting Date Range 07/16/2025 To 08/15/2025 Or until filled
All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or equivalent and above may also have obligations to not compete against 3M or solicit its employees or customers, both during their employment, and for a period after they leave 3M.
Learn more about 3M's creative solutions to the world's problems at or on Instagram, Facebook, and LinkedIn @3M.
Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties.
Safety is a core value at 3M. All employees are expected to contribute to a strong EHS culture by following safety policies, identifying hazards, and engaging in continuous improvement.
Pay & Benefits Overview: does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
**Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.**
**3M Global Terms of Use and Privacy Statement**
Carefully read these Terms of Use before using this website. Your access to and use of this website and application for a job at 3M are conditioned on your acceptance and compliance with these terms.
Please access the linked document by clicking here ( , select the country where you are applying for employment, and review. Before submitting your application, you will be asked to confirm your agreement with the terms.
At 3M we apply science in collaborative ways to improve lives daily as our employees connect with customers all around the world. Learn more about 3M's creative solutions to global challenges at or on Twitter @3M or @3MNews.
3M does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
View Now

FLEX Application Security Testing Analyst

20814 Bethesda, Maryland Marriott

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

**Additional Information**
**Job Number** 25088041
**Job Category** Information Technology
**Location** Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States, 20814VIEW ON MAP ( Full Time
**Located Remotely?** N
**Position Type** Management
This is a temporary position.
The Application Security Testing Analyst will support the assessment and improvement of Web, API, Mobile application security through hands-on security testing and code analysis. The ideal candidate will have a solid foundation in secure coding practices, vulnerability detection, and testing techniques such as SAST, DAST, and manual testing. This role is designed to offer practical experience in application security testing, with opportunities to work directly with development teams, security tools, and automation in real-world environments.
**CANDIDATE PROFILE**
**Education and Experience**
**Required:**
+ Bachelor's degree in Cybersecurity, Computer Science or related field or equivalent experience/certification
+ 2+ years of information technology or application development experience
+ Strong understanding of programming concepts (e.g., loops, data types, logic, input/output)
+ Basic experience or familiarity with application security testing tools (e.g., Burp Suite, OWASP ZAP, Fortify, Veracode)
+ Understanding of the OWASP Top 10 and common application vulnerabilities (e.g., XSS, SQLi, CSRF)
+ Basic knowledge of vulnerability triage and remediation processes
+ Familiarity with version control (e.g., Git), CI/CD concepts, and the SDLC
+ Proficiency in Microsoft Word, PowerPoint, and Excel
+ Excellent communication skills
**Preferred:**
+ Master's degree in Cybersecurity, Computer Science, or related field or equivalent experience/certification
+ Security certifications (e.g., GWAPT, OSCP, CEH, Security+, or CySA+)
+ 2+ years of experience in an application security, QA, or software testing role
+ Experience performing web application penetration testing or source code review
+ Exposure to secure SDLC practices and integrating testing into CI/CD pipelines
+ Understanding of risk scoring frameworks (e.g., CVSS) and security ticketing workflows
+ Familiarity with compliance standards such as PCI-DSS, NIST 800-53, or ISO 27001
**CORE WORK ACTIVITIES**
**Application Security Risk Management & Tracking**
+ Application Security Testing & Risk Analysis
+ Assist with static and dynamic application security testing (SAST/DAST) using tools such as CodeQL, Trivy, Dependency Check, SonarQube, and Burp Suite
+ Perform basic manual testing and validation of vulnerabilities in development and pre-production environments
+ Support secure code reviews under supervision, identifying potential security flaws in application logic or design
+ Collaborate with software developers to provide guidance on secure coding practices and vulnerability remediation
+ Triage vulnerability reports and escalate findings based on severity and impact
+ Assist in the integration of security testing tools into CI/CD pipelines and automated testing environments
+ Contribute to the development of test cases and security use cases based on threat modeling or abuse case analysis
+ Support documentation of findings, test results, and risk assessments in systems such as JIRA or ServiceNow
+ Help maintain dashboards and reporting for tracking vulnerability trends and remediation status
+ Stay current on emerging security vulnerabilities, exploits, and application security best practices
+ Work closely with the Senior Manager to continuously improve the testing processes and tool coverage
+ Participate in knowledge sharing and security training initiatives with development teams
The pay range for this position is $33.94 to $53.46 per hour.
FLEX opportunities offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.
Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD.
_Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law._
Marriott International is the world's largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. **Be** where you can do your best work, **begin** your purpose, **belong** to an amazing global team, and **become** the best version of you.
View Now

Senior Product Manager, Application Security Testing

10261 New York, New York Datadog

Posted today

Job Viewed

Tap Again To Close

Job Description

Senior Product Manager, Application Security Testing

Join to apply for the Senior Product Manager, Application Security Testing role at Datadog

Senior Product Manager, Application Security Testing

17 hours ago Be among the first 25 applicants

Join to apply for the Senior Product Manager, Application Security Testing role at Datadog

Get AI-powered advice on this job and more exclusive features.

At Datadog, we're on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. We operate at high scaletrillions of data points per dayallowing for seamless collaboration and problem-solving among Dev, Ops and Security teams globally for tens of thousands of companies. Our culture values pragmatism, honesty, and simplicity to solve hard problems the right way.

Datadogs Application Security Testing products, part of our Code Security suite, utilize both static (SAST) and runtime (IAST) scanning to detect critical vulnerabilities across the application lifecycle, from the developer IDE through CI/CD and into production environments.

As a Senior Product Manager for Application Security Testing, you will be working with a talented team of engineers and product designers to continue the evolution of one of our fastest growing new products. You will be the go-to person for our highly-motivated sales and marketing teams

At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them.

What Youll Do:

  • You will be heavily customer-focused, conducting dozens of meetings per month with current and prospective users to discover their needs, validate new feature ideas, support key sales opportunities, and share details of the product vision and roadmap.
  • Work closely with engineering and product design to define and deliver new product capabilities.
  • Partner with marketing and cross functional teams including sales, customer success , technical support and your own engineering team, to define Go-To-Market plans and strategy for our Code Security products.
  • Drive the product planning process each quarter to set objectives and key results and get buy-in from the Datadog executive team.

Who You Are:

  • You have 6+ years of experience as a Product Manager (ideally working on a developer or security-focused SaaS product)
  • You have either worked as an engineer previously or possess a deep interest, understanding and knowledge in software development and/or security.
  • You have excellent verbal and written communication skills and the willingness to present and defend your ideas to technical stakeholders, executives, and customers alike
  • You are customer-focused with high quality standards for your products
  • You are passionate to work in a high growth and impact environment to build new products and scaling existing ones
  • Bonus: You are passionate about AI and machine learning technologies and like to work hands-on to understand their capabilities and limitations.

Datadog values people from all walks of life. We know not everyone will meet all the above qualifications on day one. Thats okay. If youre passionate about technology and want to grow your experience, we encourage you to apply.

Benefits & Growth:

  • New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
  • Continuous professional development, product training, and career pathing
  • Intra-departmental mentor and buddy program for in-house networking
  • An inclusive company culture, ability to join our Community Guilds
  • Access to Inclusion Talks, our Internal panel discussions
  • Free, global Spring Health benefits for employees and dependents age 6+
  • Competitive global benefits

Benefits and Growth listed above may vary based on the country of your employment and the nature of your employment with Datadog.

Datadog offers a competitive salary and equity package, and may include variable compensation. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Datadog offers a wide range of best in class, comprehensive and inclusive employee benefits for this role including healthcare, dental, parental planning, and mental health benefits, a 401(k) plan and match, paid time off, fitness reimbursements, and a discounted employee stock purchase plan.

The reasonably estimated yearly salary for this role at Datadog is:

$187,000$40,000 USD

About Datadog:

Datadog (NASDAQ: DDOG) is a global SaaS business, delivering a rare combination of growth and profitability. We are on a mission to break down silos and solve complexity in the cloud age by enabling digital transformation, cloud migration, and infrastructure monitoring of our customers entire technology stacks. Built by engineers, for engineers, Datadog is used by organizations of all sizes across a wide range of industries. Together, we champion professional development, diversity of thought, innovation, and work excellence to empower continuous growth. Join the pack and become part of a collaborative, pragmatic, and thoughtful people-first community where we solve tough problems, take smart risks, and celebrate one another. Learn more about #DatadogLife on Instagram, LinkedIn, and Datadog Learning Center.

Equal Opportunity at Datadog:

Datadog is an Affirmative Action and Equal Opportunity Employer and is proud to offer equal employment opportunity to everyone regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, and more. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Here are our Candidate Legal Notices for your reference.

Your Privacy:

Any information you submit to Datadog as part of your application will be processed in accordance with Datadogs Applicant and Candidate Privacy Notice. Seniority level
  • Seniority level Mid-Senior level
Employment type
  • Employment type Full-time
Job function
  • Job function Product Management and Marketing
  • Industries Software Development

Referrals increase your chances of interviewing at Datadog by 2x

Sign in to set job alerts for Senior Product Manager roles.

New York, NY 175,000.00- 270,000.00 6 days ago

New York, NY 65,000.00- 129,225.00 22 hours ago

Senior Product Manager, UX Research Tooling

New York, NY 183,000.00- 271,000.00 4 days ago

Product Management Manager, Tabletop & Gift

New York, NY 62,500.00- 100,000.00 1 week ago

Holmdel, NJ 145,000.00- 150,000.00 1 week ago

New York, NY 165,000.00- 288,750.00 4 days ago

Senior Product Manager, Client Experience

New York, NY 94,000.00- 129,250.00 4 days ago

New York, NY 144,000.00- 252,000.00 6 days ago

Principal Product Manager, Core Experiences

New York, NY 252,000.00- 280,000.00 1 week ago

Product Owner I - Digital and Technology Partners - Digital Experience - Hybrid

New York, NY 109,000.00- 163,695.00 4 days ago

New York, NY 200,000.00- 275,000.00 9 months ago

Senior Product Manager, Banking & Payments

New York, NY 232,500.00- 319,000.00 6 days ago

Lead Product Manager - Data Products & Insights

New York, NY 180,000.00- 230,000.00 4 days ago

New York, NY 201,000.00- 240,000.00 2 weeks ago

New York City Metropolitan Area 55.00- 63.00 3 weeks ago

Senior Product Manager, AI Workflows (FinData)

New York, NY 169,000.00- 219,000.00 3 days ago

New York, NY 110,000.00- 140,000.00 1 month ago

Senior Product Manager - AI Guest Communications

New York, NY 160,000.00- 230,000.00 3 months ago

New York, NY 81,000.00- 147,000.00 1 week ago

Senior Product Manager, Personalization and User Experiences

New York, NY 149,000.00- 170,000.00 2 weeks ago

New York, NY 170,000.00- 215,000.00 1 week ago

Were unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr
View Now

Senior Security Engineer - Penetration Testing

80285 Denver, Colorado Rubix Recruiting

Posted 23 days ago

Job Viewed

Tap Again To Close

Job Description

Our company is extremely passionate about security and the benefit it brings to our customers.  We are aiming to bring in a mutli-tasking leader to direct and influence the next stage in our success.  

General Expectations:

  • Develop security implementations and plans
  • li>Implement Protections
  • Test for Vulnerabilities
  • Monitor for Security Breaches
Experience:
  • Direct experience with anti-virus software, intrusion detection, firewalls and content filtering
  • Knowledge of risk assessment tools, technologies and methods
  • Experience designing secure networks, systems and application architectures
  • Knowledge of disaster recovery, computer forensic tools, technologies and methods
  • Experience planning, researching and developing security policies, standards and procedures
Please contact Lane Peercy with your interest
View Now

Security Application Testing Engineer

75086 Fairview, Texas New Era Technology company

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

Join to apply for the Security Application Testing Engineer role at New Era Technology .

1 week ago Be among the first 25 applicants

Join to apply for the Security Application Testing Engineer role at New Era Technology .

Get AI-powered advice on this job and more exclusive features.

Join New Era Technology, where People First is at the heart of everything we do. With a global team of over 4,500 professionals, we're committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.

At New Era, you'll join a team-oriented culture that prioritizes your personal and professional development. Work alongside industry-certified experts, access continuous training, and enjoy competitive benefits. Driven by values like Community, Integrity, Agility, and Commitment, we nurture our people to deliver exceptional customer service.

If you want to make an impact in a supportive, growth-oriented environment, New Era is the place for you. Apply today and help us shape the future of worktogether.

Summary

We are seeking a Senior Security Test Engineer with expertise in IPv6 networking and security validation. This role involves setting up and managing an IPv6-only testing environment, performing security and functionality tests, troubleshooting issues, and documenting findings.

Primary Duties
  • Expertise in IPv6 networking and security validation is required.
  • Set up and manage the IPv6-only testing environment.
  • Perform tests to validate functionality and security, troubleshoot issues, and document findings.
  • Collaborate with Customer teams to ensure product IPv6 compatibility.
  • Address gaps affecting certification.
Experience
  • Senior Consultant with 8-10+ years in Security Application Testing.
  • Expertise in IPv6 networking and security validation is required.
Qualifications
  • Deep knowledge of IPv6 protocols, addressing, and dual-stack setups.
  • Proficiency with security testing tools like Burp Suite and OWASP ZAP.
  • Experience with network traffic analysis tools such as Wireshark.
  • Ability to configure and troubleshoot IPv6-only environments.
  • Strong test automation skills for security applications.
  • Experience with log analysis tools like ELK Stack or Splunk.
  • Knowledge of test management tools such as Jira and TestRail.
  • Ability to produce detailed technical documentation and test reports.
Education
  • Certified IPv6 Network Engineer (CNE6)
  • Certified IPv6 Security Specialist

Pay Range: $120$125 USD, based on qualifications and experience.

#J-18808-Ljbffr
View Now

Application Offensive Security Consultant | Application Security Testing

07390 Jersey City, New Jersey Macpower Digital Assets Edge

Posted 21 days ago

Job Viewed

Tap Again To Close

Job Description

Job Summary:
  • s a member of Application Security team you will provide support in offensive security assessments on applications.
  • Provide SME guidance to key projects.
  • Perform security assessments and offer technical direction.
  • Ensure security best practices in application development.
Primary Responsibilities:
  • Conduct offensive security testing on applications and APIs.
  • Perform application threat hunting to assess risks.
  • Execute manual security testing of applications.
  • Document vulnerabilities in predefined report formats using manual methods and tools.
  • Generate reports summarizing assessment findings for remediation.
  • ct as a subject matter expert for application defense enhancements.
  • Collaborate with Security Architects, Product Managers, and Risk Managers.
Talents Needed for Success:
  • Minimum 6 years of experience in web application security testing.
  • Minimum 4 years of hands-on experience with Burp Suite and OWASP ZAP .
  • bility to manually identify vulnerabilities in OWASP Top 10 without automated scanning.
  • Understanding of MITRE Framework and adversarial methodologies.
  • Bachelor's degree or equivalent experience.
Nice to Have:
  • Offensive security or penetration testing certifications.
  • Completion of penetration testing & red teaming courses.
  • Passion for Capture the Flag (CTF) challenges and platforms like TryHackMe or HackTheBox .
  • bility to multitask and work under pressure.
View Now

Application Penetration testers /Dynamic Application Security Testing (DAST)

94199 San Francisco, California Syntricate Technologies

Posted 21 days ago

Job Viewed

Tap Again To Close

Job Description

pplication Penetration testers /Dynamic Application Security Testing (DAST)
San Francisco CA or New York City, NY or Charlotte NC or Irving TX or Chandler AZ or Minneapolis MN (Hybrid 3-5 days onsite)
12+ Months
Web cam Interview

$55-$60/Hr on W2

NOT:
  • Manager mentioned he has read many resumes the past 2 weeks However many of the candidates submitted were not true application penetration testers.
  • He saw many who would classify as a QA analyst by their job classification.
  • He saw many others where they worked with third parties who did pen tests, but they never did tests themselves.
  • He is also seeing a lot of people who run vulnerability scans, however this is not Dynamic Application Security Testing (DAST).
Description:
  • In this contingent resource assignment, you may: Consult on or participate in moderately complex initiatives and deliverables within Information Security Engineering and contribute to large-scale planning related to Information Security Engineering deliverables.
  • Review and analyze moderately complex Information Security Engineering challenges that require an in-depth evaluation of variable factors.
  • Contribute to the resolution of moderately complex issues and consult with others to meet Information Security Engineering deliverables while leveraging solid understanding of the function policies procedures and compliance requirements.
  • Collaborate with client personnel in Information Security Engineering.
Required Qualifications:
  • 4 years of Information Security Engineering experience or equivalent demonstrated through one or a combination of the following: work or consulting experience training military experience education.
Skills:
The Senior Information Security Engineer will:
  • Conduct Dynamic Application Security Testing (DAST) through manual testing and by using automated testing tools
  • Review test results from tools
  • Ensure that DAST tests are completed successfully
  • Identify and remove any false positives from automated testing tool reports
  • Triage & Disposition results and enforce a Bug Bar
  • Verify/validate defect fixes
  • Provide application security consulting SME Support to developers
  • ssist developers with understanding of security defects and risk
  • ssist in defining acceptable solution to fix defects
  • Stay up to speed on 3rd party (inside and outside Wells Fargo) known security vulnerabilities
  • Develop and review malicious use cases/threat models
  • Maintain a broad understanding of security technologies and products
Requirements:
  • 5 years of information security applications and systems experience
  • 3 years of DAST Dynamic Application Security Testing experience
  • 3 years of automated information security penetration tools experience
  • Penetration testing certification such us GPEN GXPEN GWAPT or OSCP
View Now
Be The First To Know

About the latest Security testing Jobs in United States !

Principal Product Security Engineer, Penetration Testing - Minneapolis, MN

55112 Mounds View, Minnesota Medtronic

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

We anticipate the application window for this opening will close on - 26 Aug 2025
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
**A Day in the Life**
Act boldly. Compete to win. Move with speed and decisiveness. Foster belonging. Deliver results.the right way. That's the Medtronic Mindset - our cultural norms. Our brand is rooted in action, not just words. The Medtronic Mindset defines the expectations of our culture. Every person here plays a role in bringing it to life. We recognize your extraordinary potential to ensure future generations live better, healthier lives.
The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices.
The Penetration Testing team within the Product Security Office is responsible for providing attacker-like testing, product assessments, and other feedback on the security of devices for Medtronic's products to the distributed Operating Units across the organization.
The Principal Product Security Penetration Testing Engineer will execute complex testing to identify vulnerabilities in Medtronic products and assist with the identification of mitigation strategies. This testing will occur throughout a product's lifecycle for new product development and market-released products. This person will report to Enterprise Quality, members of this team will consult with product development and support organizations, scope assessments, conduct testing, summarize results, and report findings; all with a high degree of quality, autonomy, and speed.
This role requires on-site work at a Medtronic facility four days per week. Candidates must live within a reasonable commute to any Medtronic office, with a preference for those based near the Minneapolis, MN, area.
Responsibilities may include the following and other duties may be assigned.
+ Scope, conduct, and report results of product security penetration tests to key stakeholders
+ Contribute ideas to the team to help design test scenarios and improve penetration testing processes
+ Coach junior members on the team and review testing results to ensure accuracy and completeness
+ Rate the severity of vulnerabilities that are identified through testing
+ Stay up to date on current security knowledge
+ Employ a variety of test methods to perform comprehensive vulnerability assessment and penetration testing of products
+ Identify and leverage appropriate tools and techniques to accomplish testing
+ Coordinate with product development engineers to ensure understanding of findings
+ Document, communicate, and summarize the results of testing to relevant stakeholders, including formal test reports
+ Maintain awareness of existing and emerging security research and leverage that knowledge during internal testing activities (an "attacker-like" approach to testing)
+ Analyze, triage and recreate vulnerabilities submitted to Medtronic by 3rd party security researchers
+ Understand current regulations and utilize that knowledge to inform internal testing activities
+ Show creativity and innovation in all aspects of your responsibilities
+ Operate with a high level of independence
+ Contribute to Product Security Office Fiscal Year Initiatives and strategic plans
+ Support ad hoc Product Security Office campaigns and initiatives
+ Expected Travel: Up to 20%
**Must Have: Minimum Requirements:**
_To be considered for this role, please ensure the minimum requirements are evident on your resume._
+ Bachelors degree required
+ Minimum of 7 years of cybersecurity and/or secure software engineering experience
+ OR advanced degree with 5 years of cybersecurity and/or secure software engineering experience.
**Nice to Have:**
+ Experience in Product Security
+ Direct experience in penetration testing
+ Penetration Testing Certifications (e.g. CEH, OSCP, OSWA, GPEN, GMOB, Pentest+, etc.).
+ Other Information Security Certifications (e.g. Security+, CISSP, CISM, GSEC, etc.).
+ Experience assessing and testing the embedded security of regulated or safety critical devices.
+ Knowledge of the medical device industry.
+ Experience performing hardware and software penetration testing.
+ Experience working as an engineer or developer for embedded device hardware or firmware, mobile applications, web applications, or desktop applications.
+ Understanding of the security development process and product development process.
+ Ability to be creative to think "outside the box".
+ Experience facilitating working sessions.
+ Knowledge in risk management and assessment methodologies, security frameworks and relevant global regulations.
+ Strong capability to research and evaluate emerging technologies.
+ Demonstrated ability to be flexible and take a proactive approach to managing change.
+ Excellent written and verbal communication skills.
+ Experience working in a highly regulated industry and/or a formal quality system.
+ Occasional after-hours availability to accommodate different regional and global partners.
+ Strong in interpersonal communication and demonstrate a collaborative work style.
+ Comfortable working in an ambiguous environment.
+ Innovative thinker; ability to think outside of the current norms and processes
+ Independent self-starter
+ Strong communication and collaboration skills
**Physical Job Requirements**
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. 
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
**Benefits & Compensation**
**Medtronic offers a competitive Salary and flexible Benefits Package**
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$152,800.00 - $229,200.00
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans ( Medtronic**
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here ( .
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here ( a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
**We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.
**We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.
**This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will.
+ **Build** a better future, amplifying your impact on the causes that matter to you and the world
+ **Grow** a career reflective of your passion and abilities
+ **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning
These commitments set our team apart from the rest:
**Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.
**Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.
**Better outcomes for our world** . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.
**Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.
This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here ( .
For updates on job applications, please go to the candidate login page and sign in to check your application status.
If you need assistance completing your application please email
To request removal of your personal information from our systems please email
View Now

Security Engineer, AppSec Testing Automation and Insights

10261 New York, New York Amazon

Posted 23 days ago

Job Viewed

Tap Again To Close

Job Description

Description

Do you like working through abstract problems to implement creative solutions? Do you like to blend your day with both big and small issues? How does working across a variety of Amazon’s biggest teams sound?

In the Application Security Testing Automation and Insights team, our mission is to proactively secure application resources across all Amazon using deep research and scalable automation. We help our builder teams resolve issues before promoting code to production. We seek to automate difficult to identify patterns, and work with teams to make remediation fast and accurate. Our team knows few boundaries and is willing to go to any length to solve big issues.

As a member of our team, you will bring your curiosity to learn and attention to detail to execute strategies and tactics that drive security and efficiency across all areas. You will work in a collaborative team environment, operating autonomously and leading your own projects with some guidance under more tenured engineers. You will define guidance and remediation for our vast engineering community to implement. You will help raise the security bar across many of your favorite businesses. If you want to be apart of this fast paced, challenge driven team apply below. You will fearlessly drive Amazon’s security bar and high standards.

Key job responsibilities

• Develop, curate, and improve highly scalable application security rules to identify coding and configuration flaws

• Evaluate and recommend new security testing tools

• Deep dive code and research application frameworks to identify weaknesses and detection opportunities

• Leverage application system telemetry to extract insights and identify vulnerabilities

• Analyze and secure our applications during runtime

• Detect perimeter exposures

• Develop, enhance, and interpret security standards and guidance

• Demonstrate and promote security best practices, drive improvements of Amazon’s overall security architecture

About the team

About Amazon Security

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

#JoinStoresAppSec

Basic Qualifications

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience

  • Bachelor's degree in computer science or equivalent

  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP

Preferred Qualifications

  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

  • Experience with AWS products and services

  • Experience with programming languages such as Python, Java, C+Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.

View Now

Security Engineer, AppSec Testing Automation and Insights

98127 Seattle, Washington Amazon

Posted 23 days ago

Job Viewed

Tap Again To Close

Job Description

Description

Do you like working through abstract problems to implement creative solutions? Do you like to blend your day with both big and small issues? How does working across a variety of Amazon’s biggest teams sound?

In the Application Security Testing Automation and Insights team, our mission is to proactively secure application resources across all Amazon using deep research and scalable automation. We help our builder teams resolve issues before promoting code to production. We seek to automate difficult to identify patterns, and work with teams to make remediation fast and accurate. Our team knows few boundaries and is willing to go to any length to solve big issues.

As a member of our team, you will bring your curiosity to learn and attention to detail to execute strategies and tactics that drive security and efficiency across all areas. You will work in a collaborative team environment, operating autonomously and leading your own projects with some guidance under more tenured engineers. You will define guidance and remediation for our vast engineering community to implement. You will help raise the security bar across many of your favorite businesses. If you want to be apart of this fast paced, challenge driven team apply below. You will fearlessly drive Amazon’s security bar and high standards.

Key job responsibilities

• Develop, curate, and improve highly scalable application security rules to identify coding and configuration flaws

• Evaluate and recommend new security testing tools

• Deep dive code and research application frameworks to identify weaknesses and detection opportunities

• Leverage application system telemetry to extract insights and identify vulnerabilities

• Analyze and secure our applications during runtime

• Detect perimeter exposures

• Develop, enhance, and interpret security standards and guidance

• Demonstrate and promote security best practices, drive improvements of Amazon’s overall security architecture

About the team

About Amazon Security

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

#JoinStoresAppSec

Basic Qualifications

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience

  • Bachelor's degree in computer science or equivalent

  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP

Preferred Qualifications

  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

  • Experience with AWS products and services

  • Experience with programming languages such as Python, Java, C+Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit . This position will remain posted until filled. Applicants should apply via our internal or external career site.

View Now
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Testing Jobs