This position is for a Penetration Engineer II. The role involves managing program assessments from initial planning, scheduling, and communications with systems owners and related stakeholders through to final reporting. The engineer will prepare required assessment documentation and assist in process improvement and automation for the assessment methodology. Key responsibilities include conducting assessments of client and contractor hardware to ensure compliance with security requirements, analyzing and determining compliance with applicable federal and legislative regulations. The role requires partnering with other cybersecurity and development teams to identify business-critical/high-risk assets such as web/mobile applications, servers, networks, Point of Sales machines, and robots. The engineer will perform in-depth security assessments and penetration testing of these assets as per OWASP top ten, SANS top twenty-five, HIPPA, and PCI DSS standards. This includes identifying and exploiting vulnerabilities in commercial, open source, and custom software applications, infrastructure, people, and processes across one of the world’s largest networks. The position also entails composing test reports, recording vulnerability data according to Governance, Risk, and Compliance (GRC) processes, and delivering technical debriefs to engineers/developers to aid in fixing identified vulnerabilities. Additionally, the engineer will evaluate and maintain testing tools, hardware, and equipment, creating new tools where appropriate.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level