Security Consultant – Penetration Testing, DevSecOps

🕒 September 16

🏈 Alabama, California, +15 more states – Remote

infoinfo

💵 $70.2k - $170k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

⛑ DevOps & Site Reliability Engineer (SRE)

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 2%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Capgemini

Capgemini

10,000+ employees

Founded 1967

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

Capgemini is a global leader in partnering with businesses to transform and manage their operations by harnessing the power of technology. With expertise across a wide array of industries such as aerospace, automotive, banking, and healthcare, Capgemini provides a constantly evolving portfolio of services to meet the ever-changing needs of their clients. Their offerings include cloud, cybersecurity, data and artificial intelligence, and enterprise management, among others. Capgemini also emphasizes innovation and sustainability, helping companies achieve digital transformation while promoting environmental and social responsibility. Additionally, Capgemini provides career opportunities across various levels and professions, encouraging innovation and diversity in its workforce.

📋 Description

• Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure • Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation using OWASP, PTES, NIST, and MITRE ATT&CK methodologies • Identify vulnerabilities, validate exploitability, assess business risk, and provide remediation recommendations • Execute assessments of microservices, containers, Kubernetes, and cloud-native applications • Develop proof-of-concepts demonstrating security weaknesses and attack paths • Prepare detailed technical reports and executive summaries • Integrate security controls and testing into CI/CD pipelines • Implement and manage SAST, DAST, SCA, IaC, container security, secrets detection, and API security testing solutions • Collaborate with development teams on vulnerability remediation and secure coding practices • Participate in security architecture reviews, threat modeling, and secure design assessments • Automate security testing and compliance validation within DevOps toolchains • Develop security guardrails and policy-as-code capabilities • Perform vulnerability triage, risk prioritization, and remediation tracking • Support continuous security monitoring and risk assessment • Analyze emerging threats and security trends to improve testing methodologies • Assist with security standards, procedures, and best practices • Work with engineering, cloud, and infrastructure teams to improve organizational security posture • Present findings and recommendations to developers, architects, engineering teams, and leadership • Provide security consulting throughout the software development lifecycle

🎯 Requirements

• Bachelor's degree in Computer Science, Information Security, Engineering, or a related field • 5–8 years of hands-on cybersecurity experience • Minimum 3+ years conducting application and API penetration testing • Experience implementing or supporting DevSecOps initiatives within CI/CD environments • Strong understanding of web application security, API security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, threat modeling, and vulnerability management • Hands-on experience with Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins • One or more of the listed security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty; OSCP is preferred • Experience with container security, including Docker and Kubernetes • Experience conducting cloud penetration testing • Understanding of Infrastructure as Code, including Terraform and CloudFormation • Familiarity with Red Team methodologies and adversary simulation • Exposure to Zero Trust Architecture and Secure-by-Design principles • Excellent communication, consulting, and stakeholder management skills

🏖️ Benefits

• Paid time off: vacation (12–25 days depending on grade), company-paid holidays, personal days, and sick leave • Medical, dental, and vision coverage (or provincial healthcare coordination in Canada) • Retirement savings plans (401(k) in the U.S.; RRSP in Canada) • Life and disability insurance • Employee assistance programs • Other benefits as provided by local policy and eligibility • Potential eligibility for variable incentives, bonuses, or commissions

Apply Now

Similar Jobs

🕒 September 15

Zocdoc

501 - 1000

🏥 Healthcare

⚕️ Healthcare Insurance

🏪 Marketplace

Senior Site Reliability Engineer maintaining distributed AWS/GCP infrastructure and uptime. Supporting Zocdoc’s digital health marketplace serving millions of patients and providers.

🕒 September 15

Tradeify

51 - 200

💳 Fintech

💸 Finance

DevSecOps Engineer owning AWS infrastructure, CI/CD, and security operations for Tradeify’s high-performance futures and crypto trading platform. Improving reliability, observability, vulnerability management, and incident response.

🕒 September 15

Solventum

10,000+ employees

🏥 Healthcare

📦 Logistics

💼 Consulting

Site Reliability Engineer supporting Solventum’s healthcare speech products. Maintaining production systems, monitoring, alerting, and cloud infrastructure with AWS and Kubernetes.

🕒 September 15

Megaport

201 - 500

📡 Telecommunications

Senior Site Reliability Engineer improving reliability, resilience, and observability for Megaport’s global Network as a Service infrastructure. Automating production systems across cloud and Kubernetes environments.

🕒 September 15

FindErnest

11 - 50

💼 Consulting

🏢 Enterprise

🤝 B2B

DevOps Lead managing production Azure AKS environments and advanced Terraform IaC for IT services. Driving Flux CD, Helm, Dynatrace observability, CI/CD, security, and team performance.