Security Consultant – Penetration Testing, DevSecOps

🔥 16 hours ago

🏈 Alabama, Arizona, +17 more states – Remote

infoinfo

💵 $70.2k - $170k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

⛑ DevOps & Site Reliability Engineer (SRE)

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 2%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Capgemini

Capgemini

10,000+ employees

Founded 1967

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

Capgemini is a global leader in partnering with businesses to transform and manage their operations by harnessing the power of technology. With expertise across a wide array of industries such as aerospace, automotive, banking, and healthcare, Capgemini provides a constantly evolving portfolio of services to meet the ever-changing needs of their clients. Their offerings include cloud, cybersecurity, data and artificial intelligence, and enterprise management, among others. Capgemini also emphasizes innovation and sustainability, helping companies achieve digital transformation while promoting environmental and social responsibility. Additionally, Capgemini provides career opportunities across various levels and professions, encouraging innovation and diversity in its workforce.

📋 Description

• Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure • Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities using OWASP, PTES, NIST, and MITRE ATT&CK methodologies • Identify vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations • Execute security assessments of microservices, containers, Kubernetes, and cloud-native applications • Develop proof-of-concepts demonstrating security weaknesses and attack paths • Prepare detailed technical reports and executive summaries for customers and stakeholders • Integrate security controls and testing into CI/CD pipelines • Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions • Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices • Participate in security architecture reviews, threat modeling exercises, and secure design assessments • Automate security testing and compliance validation within DevOps toolchains • Develop security guardrails and policy-as-code capabilities • Perform vulnerability triage, risk prioritization, and remediation tracking • Support continuous security monitoring and risk assessment activities • Analyze emerging threats, attack techniques, and security trends • Assist in developing security standards, procedures, and best practices • Work with engineering, cloud, and infrastructure teams to enhance organizational security posture • Present findings and recommendations to developers, architects, engineering teams, and leadership • Provide security consulting throughout the software development lifecycle

🎯 Requirements

• Bachelor's degree in Computer Science, Information Security, Engineering, or a related field • 5-8 years of hands-on cybersecurity experience • Minimum 3+ years of experience conducting application and API penetration testing • Experience implementing or supporting DevSecOps initiatives within CI/CD environments • Strong understanding of Web Application Security, API Security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, Threat Modeling, and Vulnerability Management • Hands-on experience with Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins • One or more listed security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty • Experience with container security (Docker, Kubernetes) • Experience conducting cloud penetration testing • Understanding of Infrastructure as Code (Terraform, CloudFormation) • Familiarity with Red Team methodologies and adversary simulation • Exposure to Zero Trust Architecture and Secure-by-Design principles • Experience with AI/LLM security testing is a plus • Excellent communication, consulting, and stakeholder management skills

🏖️ Benefits

• Vacation: 12-25 days, depending on grade • Company paid holidays • Personal Days • Sick Leave • Medical, dental, and vision coverage (or provincial healthcare coordination in Canada) • Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada) • Life and disability insurance • Employee assistance programs • Other benefits as provided by local policy and eligibility • Variable incentives, bonuses, or commissions may be available

Apply Now

Similar Jobs

🔥 20 hours ago

Alight Solutions

10,000+ employees

🤝 B2B

🏥 Healthcare

☁️ SaaS

Azure DevOps Engineer scaling Azure/AWS infrastructure and CI/CD for Alight’s healthcare and workforce benefits services. Supporting Terraform, ETL, compliance, observability, and production reliability.

🇺🇸 United States – Remote

💵 $120k - $150k / year

💰 $22.5M Post-IPO Secondary - Alight Solutions on 2023-08

⏰ Full Time

🟡 Mid-level

🟠 Senior

⛑ DevOps & Site Reliability Engineer (SRE)

🔥 21 hours ago

General Dynamics Information Technology

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Senior Oracle DevOps Engineer automating deployment pipelines for GDIT’s CMS healthcare technology program. Managing FlexDeploy, GitLab, DevSecOps controls, and Oracle application releases.

🕒 Yesterday

VIATEQ Corporation

11 - 50

🏛️ Government

🎖️ Defense

💼 Consulting

Senior AWS SRE supporting federal government digital services through AWS, Kubernetes, automation, and observability. Improving platform reliability, security, and operational readiness.

🕒 Yesterday

Frontier Airlines

5001 - 10000

✈️ Travel

📦 Logistics

🚗 Transport

Lead SRE ensuring reliable AWS and Kubernetes platforms for Denver-based Frontier Airlines. Driving automation, observability, incident response, and enterprise cloud resilience for airline operations.

🕒 Yesterday

Independence Pet Group

1001 - 5000

🛡️ Insurance

👥 B2C

🧘 Wellness

DevOps Engineer building governed Azure infrastructure and CI/CD for Independence Pet Holdings’ pet health brands. Delivering Terraform, DevSecOps, monitoring, and operational support.