Senior Penetration Tester
Job Description
ABOUT THE ROLE
As a Senior Penetration Tester with A-LIGN, you will be part of a dedicated pen testing team whose sole purpose is to test and improve the security of our clients’ systems and data across a wide range of industries. This is not an entry level position, but a position open for an experienced, seasoned or specialized hacker. If you have an appetite for penetration testing and want to build your knowledgebase and skillset; this position is for you.
ABOUT YOU:
- Passionate about information security and identifying exploitable vulnerabilities before threat actors can take advantage of them
- Ready to find more efficient ways to accomplish your work
- Continuous desire to grow, develop and advance skills
- Can work independently, or collaboratively with the team
- Desire to provide highest quality test and deliverables to clients without cutting corners
- Proficiency with scripting languages (Python, Bash, JavaScript, PowerShell)
- Self-driven in a remote working environment, motivation to continuously provide high quality work and deliverables
- You enjoy hacking (ethical), follow threat feeds, latest threat trends, know a thing or two about exploits (or have written some yourself)
- You enjoy working in a group, and believe in open collaboration as a team.
- You enjoy sharing knowledge and lessons learned, you like to share the specialized knowledge or skills you may have with the team
- You don’t make excuses for a difficult challenge, you make scripts instead.
- You know the OWASP top 10 and SANS top 20, and have an opinion about one vs the other.
MINIMUM QUALIFICATIONS
- Master’s or Bachelor’s degree in cybersecurity, management information systems, computer science, or relevant discipline.
- Two of the following penetration certifications required: GWAPT, CEPT, LPT, GPEN, CPT, GXPN, PenTest+, GAWN, GMOB, CRTOP
- Proficiency with scripting languages (Python, Bash, JavaScript, powershell)
- Knowledge of incident response/forensics/red-teaming or DevOps a huge plus but not required.
- You have 5+ years of experience with penetration tests and vulnerability assessments; including internal, external, wireless, mobile, and web application testing.
- You have an understanding of API’s, how they work, and how to test them.
- You have used cloud CSP’s such as AWS, Azure, AliCloud, Google cloud, Rackspace, and any internal associated components/controls.
- You can perform social engineering campaigns including phishing, vishing, and physical.
- You can re-image your own system when necessary, and navigate Kali Linux to conduct penetration tests, with only command line access as necessary.
- You can create, modify, and write documents from command line, and write Bash scripts to automate or facilitate tasks as necessary.
- You can write professional reports with proper grammar, spelling, and punctuation, that need very little QA review.
- You can communicate with clients, and understand if something needs to be escalated internally.
- You are comfortable monitoring the metrics of a project, personal utilization, and constant improvement toward efficiency.
- You are willing to expand your knowledge, obtain relevant certifications, and meet CPE requirements as necessary.
- You are ready and willing to learn, and accept a new challenge.
- You have three or more certifications such as CEH, OSCP, OSCE, GWAPT, GPEN, CEPT, LPT, CPT, GXPN, PenTest+, GAWN, GMOB, CRTOP
Skills:
- You have working knowledge of Kali Linux and standard security assessment tools (e.g., NMAP, metasploit, Scapy, Burp Suite, SSLStrip, Ettercap, Nessus, Nikto, AppScan) and can talk about any others you have used.
- You have strong written and verbal communication skills.
- You can run scans and perform tests with minimal impact to client networks.
- You have an understanding of both iOS and Android application testing, and how to jailbreak/root devices, use emulators.
- You know about SOAP/REST/JSON web APIs and how to test them.
- You have experience using interpreted languages (Ruby, Python, PHP, etc.)
- You can explain findings in a non-technical form.
The ideal candidate may also have:
- Programming experience in one or more of the following languages: Ruby, Python, Perl, C, C++, Java, and C#
- Knowledge of network protocol design, or zero day exploitation
- Know about static code analysis and have used SCA tools
- You have soldered to a device to exploit it, or extract information from an embedded device.
- You are an innovator, you feel something is missing, and want to create it.
- Want to work in IoT, embedded testing, or research niche threat and exploitation for the future.
REPORTS TO: Managing Consultant
PAY CLASSIFICATION: Full-Time, Exempt
RESPONSIBILITIES
- Execute internal, external, wireless, mobile, API and web application pen tests.
- Execute social engineering tests, including phishing, vishing, and physical.
- Execute vulnerability scans and assessments.
- Compile and write client reports
BENEFITS
- 24 days Annual PTO
- Annual Bonus Program
- Fully Covered Additional Health Insurance, Visual and Dental
- Multisport Card
- Public Transportation Card Reimbursement
- Paid Office Closure December 24 - January 1
- Paid Holidays Schedule
- Employee Assistance Program
- Monthly Technical Allowance
- Certification Reimbursement
- Flu Shot Reimbursement
HOW DO WE EVALUATE CANDIDATES?
We are looking for individuals who can demonstrate they have the knowledge, skills, and abilities that are needed to perform their job successfully. These core competencies include:
- Knowing My Organization – Do you demonstrate an understanding of A-LIGN’S product/service offerings? Are you able to leverage organizational values in how work is accomplished?
- Focusing on Customers – Do you understand and anticipate customer needs? Are you able to develop a positive relationship with the customers? Do you provide high-quality products and services to exceed expectations?
- Showing Resilience – Do you convey a clear sense of self-confidence to influence future events? Are you able to stay calm and composed under pressure? Do you effectively resolve conflicts and disagreements?
- Engendering Confidence and Trust – Do you instill confidence and trust by demonstrating dependability and reliability? Do you portray trustworthiness by being open and honest?
- Processing Details – Do you ensure projects are completed on time by keeping work on schedule? Are you able to thoroughly work on tasks and provide high quality work? Do you follow rules and established processes to minimize risks?
- Structuring Tasks – Do you plan your work and set clear priorities? Are you able to uphold ethical standards and fulfill commitments while maintaining high levels productivity and output?
ABOUT A-LIGN
A-LIGN is a technology-enabled security and compliance partner trusted by more than 2,400 global organizations to confidently mitigate cybersecurity risks. We work with small businesses to global enterprises with services spanning across SOC, Penetration Testing, PCI DSS, HITRUST, ISO and privacy compliance. Our proprietary compliance management platform is transforming the compliance experience by enabling an anytime, anywhere approach to audits. For more information, visit www.A-LIGN.com.
The personal data you provide to us is processed by A-LIGN Bulgaria. Your personal data is shared with employees of A-LIGN, and the candidate data retention period is 6 months. You have the right to obtain information about the processing of your personal data. In addition, you have the right to correct, to block, and to delete your data in accordance with the local laws and regulations. For more information you can visit A-LIGN’s Privacy Policy.
Come Work for A-LIGN!
Apply online today at A-LIGN.com and learn about life at A-LIGN by following our Careers at A-LIGN LinkedIn!
A-LIGN is an Equal Opportunity Employer! Minorities, women, disabled, and veterans encouraged to apply!
Date Posted
08/12/2024
Views
3
Similar Jobs
Senior Finance Business Partner (d/f/m) - Personio
Views in the last 30 days - 0
Personio an intelligent HR platform is seeking a Senior Manager for FPA to lead financial planning and analysis for key departments The ideal candidat...
View DetailsSenior Lead, Talent Acquisition - Sales (Relocation to Munich) (d/f/m) - Personio
Views in the last 30 days - 0
Personio a leading HR platform is seeking a Senior Lead Talent Acquisition professional to drive growth in the Revenue and Success functions across Eu...
View DetailsSenior Pricing Analyst - Cencora
Views in the last 30 days - 0
Cencora formerly known as AmerisourceBergen is a leading global pharmaceutical solutions organization They are currently experiencing rapid growth in ...
View DetailsSenior Product Analyst - FinCrime Platform - WISE
Views in the last 30 days - 0
Wise is seeking a Senior Product Analyst for its FinCrime Platform The role involves driving analytics efforts in the Financial Crime Platform product...
View DetailsSenior Data Analyst - Customer Experience - WISE
Views in the last 30 days - 0
Wise is a global technology company aiming to revolutionize international money transfers by offering minimal fees maximum ease and full speed They ar...
View DetailsSenior Software Engineer (Scala/Java) - HERE Technologies
Views in the last 30 days - 0
HERE Technologies is seeking an experienced backend engineer with strong Java or Scala skills to join the Map Processing Pipelines team The role invol...
View Details