Security Engineer – Penetration Testing

🕒 June 26

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ISC2

ISC2

201 - 500 employees

Founded 1989

🔒 Cybersecurity

📚 Education

☁️ SaaS

Cybersecurity • Education • SaaS

ISC2 is a leading organization dedicated to advancing cybersecurity education and certification. They provide various programs for individuals at different stages of their cybersecurity careers, including certification exams, training resources, and leadership development opportunities. ISC2 also advocates for members and promotes diversity within the cybersecurity field by empowering professionals and communities.

📋 Description

• Plan, execute, and document internal and external penetration tests against ISC2 applications, networks, cloud environments, and infrastructure. • Perform vulnerability assessments and validate findings to distinguish genuine risks from false positives. • Conduct web application, API, mobile, and network vulnerability assessments using industry-standard methodologies (OWASP, PTES, OSSTMM). • Perform social engineering assessments, including phishing simulations and physical security testing as authorized. • Produce clear, actionable written reports detailing findings, risk ratings, evidence, and remediation recommendations tailored to both technical and executive audiences. • Support red team exercises and adversary simulation activities to test detection and response capabilities. • Own remediation follow-through: translate pen test findings into security engineering work items, validate fixes, and track resolution to closure in Jira Service Management. • Design and implement security controls across ISC2’s cloud and on-premises environments, including hardening configurations for Azure, Okta, SentinelOne, CheckPoint, and F5 XD. • Maintain awareness of emerging vulnerabilities, exploits, and threat actor TTPs; operationalize threat intelligence into actionable hardening and detection improvements.

🎯 Requirements

• Proficiency with penetration testing tools including Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike, and similar offensive frameworks. • Strong understanding of web application vulnerabilities (OWASP Top 10), network protocols, Active Directory attack paths, and cloud security (Azure, AWS, GCP). • Effective written and verbal communication with cross-functional teams is essential. • Scripting and automation proficiency in Python, Bash, or PowerShell; ability to write or modify exploit code as well as defensive tooling. • Familiarity with MITRE ATT&CK, CVSS, CVE, NIST SP 800-115, and the CIS Benchmarks for secure configuration baselines. • Posess AI literacy and ability to test Ai workloads and infrastructures. • Relevant certifications strongly preferred: OSCP, GPEN or GWAPT, plus one engineering/architecture credential (CISSP, CSSLP, or equivalent). • ISC2 membership or certifications (CISSP, CC) are a plus and demonstrate alignment with ISC2’s mission.

🏖️ Benefits

• Health insurance • Paid time off • Professional development opportunities

Apply Now

Similar Jobs

🕒 June 26

DigitalOcean

1001 - 5000

☁️ SaaS

Senior Product Security Engineer at DigitalOcean responsible for security risk assessments and mitigations in virtualization stack. Collaborating with engineers to develop secure-by-design products within a dynamic team environment.

🕒 June 26

CannonDesign

1001 - 5000

💼 Consulting

🏥 Healthcare

🏗️ Construction

Project Electrical IV at CannonDesign supporting design and delivery of complex projects. Collaborating with multidisciplinary teams and providing technical leadership throughout project delivery.

🕒 June 26

LanceDB

11 - 50

🤖 Artificial Intelligence

🏢 Enterprise

☁️ SaaS

Senior Security Engineer managing security tooling for LanceDB platform. Driving results to enhance security posture in collaboration with engineering teams.

🕒 June 26

SCAN

1001 - 5000

🏥 Healthcare

⚕️ Healthcare Insurance

👥 B2C

AI Security Engineer focusing on AI adoption and cybersecurity compliance within healthcare. Evaluating AI vendors, guiding implementation, and managing AI-related security risks.

🕒 June 26

Charlie Health

501 - 1000

🏥 Healthcare

⚕️ Healthcare Insurance

🧘 Wellness

Senior Corporate Security Engineer designing and operating security systems while partnering with IT Engineering and Compliance teams at Charlie Health.