Senior Penetration Testing Associate conducting penetration tests at cybersecurity firm Drawbridge. Collaborating with clients to assess security and improve defenses against cyber threats.
Responsibilities
Conduct internal and external penetration tests across diverse client environments.
Qualify testing requirements and scope engagements with clients.
Troubleshoot and resolve testing issues independently.
Present detailed assessment reports and findings directly to clients.
Consult with clients regarding remediation strategies and best practices.
Act as an escalation point for analysts and associates, providing technical guidance and mentorship.
Manage test scheduling and set client timing expectations to ensure smooth project delivery.
Serve as a technical consulting resource for both internal teams and external clients.
Lead penetration testing efforts against Drawbridge systems and other critical infrastructure.
Perform customized tests for clients, including physical assessments, laptop testing, remote access testing, and cloud environment evaluations.
Create and update relevant internal documentation, ensuring accuracy and completeness.
Develop repeatable and teachable processes for performing various testing tasks.
Assist in improving the organization’s penetration test offerings, including reporting and process enhancements.
Lead breach response discussions and provide advisory services during incident response engagements.
Requirements
5+ years of offensive security experience, with a focus on penetration testing.
Deep knowledge of penetration testing principles, tools, and techniques (e.g., Metasploit, Burp Suite, etc.).
Ability to identify systemic security issues based on vulnerability and configuration analysis.
Experience with Linux and Windows operating systems.
Strong working knowledge of networking concepts and attack stages (footprinting, scanning, enumeration, gaining access, privilege escalation, maintaining access, network exploitation, covering tracks).
Excellent written and verbal communication skills, with the ability to present findings to technical and non-technical audiences.
Strong ability to prioritize, organize, and multi-task in a fast-paced environment.
Experience mentoring junior team members and acting as a technical escalation point.
Excellent written and verbal communication skills.
Excellent time management skills.
Nice if you have experience with IT infrastructure, cloud technology, business continuity, disaster recovery, and incident response.
Knowledge of hedge fund, private equity, or RIA operations/compliance.
Industry certifications (e.g., OSCP, GPEN, CEH).
Experience with Python or comparable scripting language.
Benefits
Competitive compensation package
Employer 401(k) Contribution
Benefits including Medical, Dental, Vision Coverage and Life Insurance
Generous Paid Time Off Policy
Employee Assistance Program (with focus on mindfulness and well-being)
Life Insurance & Personal Accident Insurance
Health Savings Account (HSA) or Flexible Spending Account (FSA)
Senior Network Security Engineer designing and implementing network security systems for clients in Greece and abroad. Leading a small team and providing technical support.
Senior Security Engineer at Flanks leading security initiatives in a fast - paced fintech startup. Evolving security practices and collaborating with teams to implement best practices across stacks.
CISO for France driving cybersecurity strategy at Once For All's SaaS platform in construction. Collaborate with teams to manage security and compliance across operations.
Security Consultant at Kyndryl defining security policies and managing incident responses for clients. Collaborating on security measures and conducting audits to safeguard sensitive data.
Senior Staff Engineer at GEICO designing intelligent cybersecurity automation systems. Collaborating across teams to enhance security architecture and improve production readiness.
Senior Network Security Engineer managing and supporting Palo Alto firewalls across enterprise environments. Leading firewall migrations and ensuring operational effectiveness in network security.
Cybersecurity Expert leading the establishment of a FedRAMP - compliant SOC at Philips, a health technology company, while managing various cybersecurity initiatives.
Cybersecurity Engineer developing cloud - based security architectures for critical DoD systems. Responsible for securing cloud infrastructure and automating security processes in innovative technology environments.
Technical Program Manager leading strategic cloud security initiatives for global enterprises. Orchestrating diverse teams and delivering innovative products to protect critical data and infrastructure.