Security Engineer – Penetration Testing

🕒 vor 1 Monat

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

🔧 QA-Ingenieur (Qualitätssicherung)

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of ISC2

ISC2

201 - 500 Mitarbeiter

Gegründet 1989

🔒 Cybersecurity

📚 Bildung

☁️ SaaS

Cybersecurity • Education • SaaS

ISC2 ist eine führende Organisation, die sich der Förderung der Bildung und Zertifizierung im Bereich der Cybersicherheit widmet. Sie bieten verschiedene Programme für Personen in unterschiedlichen Phasen ihrer Cybersicherheitskarriere an, einschließlich Prüfungen zur Zertifizierung, Schulungsressourcen und Möglichkeiten zur Führungskräfteentwicklung. ISC2 setzt sich auch für ihre Mitglieder ein und fördert die Vielfalt im Bereich der Cybersicherheit, indem sie Fachleute und Gemeinschaften stärkt.

Beschreibung

• Plan, execute, and document internal and external penetration tests against ISC2 applications, networks, cloud environments, and infrastructure. • Perform vulnerability assessments and validate findings to distinguish genuine risks from false positives. • Conduct web application, API, mobile, and network vulnerability assessments using industry-standard methodologies (OWASP, PTES, OSSTMM). • Perform social engineering assessments, including phishing simulations and physical security testing as authorized. • Produce clear, actionable written reports detailing findings, risk ratings, evidence, and remediation recommendations tailored to both technical and executive audiences. • Support red team exercises and adversary simulation activities to test detection and response capabilities. • Own remediation follow-through: translate pen test findings into security engineering work items, validate fixes, and track resolution to closure in Jira Service Management. • Design and implement security controls across ISC2’s cloud and on-premises environments, including hardening configurations for Azure, Okta, SentinelOne, CheckPoint, and F5 XD. • Maintain awareness of emerging vulnerabilities, exploits, and threat actor TTPs; operationalize threat intelligence into actionable hardening and detection improvements.

🎯 Anforderungen

• Proficiency with penetration testing tools including Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike, and similar offensive frameworks. • Strong understanding of web application vulnerabilities (OWASP Top 10), network protocols, Active Directory attack paths, and cloud security (Azure, AWS, GCP). • Effective written and verbal communication with cross-functional teams is essential. • Scripting and automation proficiency in Python, Bash, or PowerShell; ability to write or modify exploit code as well as defensive tooling. • Familiarity with MITRE ATT&CK, CVSS, CVE, NIST SP 800-115, and the CIS Benchmarks for secure configuration baselines. • Posess AI literacy and ability to test Ai workloads and infrastructures. • Relevant certifications strongly preferred: OSCP, GPEN or GWAPT, plus one engineering/architecture credential (CISSP, CSSLP, or equivalent). • ISC2 membership or certifications (CISSP, CC) are a plus and demonstrate alignment with ISC2’s mission.

🏖️ Vorteile

• Health insurance • Paid time off • Professional development opportunities

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 1 Monat

Reddit, Inc.

501 - 1000

💼 Beratung

📣 Marketing

📱 Medien

Machine Learning Engineer responsible for designing optimization algorithms for Reddit Ads auction systems. Collaborating with cross-functional teams to enhance advertising performance metrics.

🇺🇸 Vereinigte Staaten – Remote

💵 $185.800 - $303.400 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

🔧 QA-Ingenieur (Qualitätssicherung)

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

NeueHealth

1001 - 5000

🏥 Gesundheitswesen

⚕️ Krankenversicherung

💸 Finanzen

Software Tester focused on software testing and integration of healthcare products at NeueHealth. Collaborating with teams to ensure quality in a variety of software projects.

🇺🇸 Vereinigte Staaten – Remote

💵 $88.000 - $132.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

🔧 QA-Ingenieur (Qualitätssicherung)

🗣️🇺🇸🇬🇧 Englisch erforderlich

Selenium

🕒 vor 1 Monat

HeadSpin

201 - 500

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Manual QA Engineer handling functional and exploratory testing for production issues and new features. Validating outputs and workflows while ensuring compliance and quality in software.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

Blue Cross and Blue Shield of Louisiana

1001 - 5000

🏥 Gesundheitswesen

🛡️ Versicherung

⚕️ Krankenversicherung

Lead Software Quality Assurance Engineer responsible for automated solutions and QA processes. Collaborating with teams to ensure quality needs are met in software delivery.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

Gray Media

1001 - 5000

📣 Marketing

💼 Beratung

🍽️ Lebensmittel & Getränke

Digital QA Analyst ensuring quality and accessibility of digital products for Gray Media Group. Collaborating with teams to validate product readiness and improve processes.

🇺🇸 Vereinigte Staaten – Remote

💵 $70.000 - $80.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

🔧 QA-Ingenieur (Qualitätssicherung)

🗣️🇺🇸🇬🇧 Englisch erforderlich