Security Engineer leading internal penetration testing efforts to protect complex systems. Collaborating with SRE team to proactively hunt for weaknesses across applications, cloud infrastructure, and APIs.
Responsibilities
Lead Internal Penetration Testing: Perform deep-dive manual and automated penetration tests on web applications, mobile apps, and microservices.
Adversarial Emulation: Design and execute red-team scenarios to test the organization’s detection and response capabilities.
Vulnerability Management & Exploitation: Beyond scanning, validate and exploit findings to demonstrate real-world risk and prioritize remediation for engineering teams.
Secure Architecture Review: Conduct threat modeling and architectural "stress tests" to identify logic flaws in new features before a single line of code is deployed.
Automated Offensive Tooling: Develop custom scripts and integrate offensive security tools (DAST, IAST) into the CI/CD pipeline to catch "low-hanging fruit" automatically.
Remediation Advocacy: Partner with developers to provide "exploit-to-fix" guidance, ensuring they understand the how and why behind security patches.
Incident Support: Act as a subject matter expert during security incidents to help analyze attack vectors and post-mortem findings.
Requirements
3+ years of specialized experience in Penetration Testing, Offensive Security, or Application Security.
Expert-level proficiency with the "Hacker’s Toolkit": Burp Suite Professional, Metasploit, Nmap, SQLmap, and various proxy tools.
Good Scripting Skills: Ability to write custom exploits or automation scripts in Python, Go, or Bash.
CISA Auditor focusing on cloud security audits for a Zurich - based international bank. Ensuring cybersecurity and identifying vulnerabilities in IT systems with risk - oriented audits.
Cybersecurity Specialist managing compliance for DoD security transition to Zero Trust Architecture. Involves overseeing RMF activities and ensuring ATO deadlines are met in cloud environments.
Engineer II responsible for managing enterprise customer support in Security Engineering. Focused on troubleshooting and diagnosing security incidents in a hybrid work environment.
Guest Safety Agent at HRI Hospitality ensuring safety and hospitality for guests and managing outlet spaces. Maintaining a secure environment while engaging with guests and visitors in New Orleans.
Cybersecurity Architect for Saint Louis University developing and assessing security strategies and architecture. Ensuring secure IT services through effective security technologies and practices.
Senior Commercial Manager developing and executing Cyber Security strategies, managing client portfolios and leading complex negotiations in São Paulo.
Security Officer responsible for maintaining safety at WarHorse Casino. Enforcing policies, responding to incidents, and providing customer service to guests.
Manager overseeing global cybersecurity risk management at Warner Bros. Discovery. Driving risk assessments and mitigation activities while collaborating with business stakeholders.
Cyber Security Engineer at MSSP responsible for protecting client assets and information using advanced security measures. Collaborating with teams to analyze threats and recommend mitigations.
Security Engineer developing and delivering security awareness programs and hands - on IAM configurations at CFC. Playing a key role in strengthening the organization's security posture.