Tech Stack
AWSAzureCloudCyber SecurityKubernetesSDLC
About the role
- Lead the effort to define and mature Delinea’s Penetration Testing function and provide technical expertise and programmatic structure
- Partner closely with Cybersecurity, Product, and IT teams to develop and implement continuous penetration testing across the application portfolio
- Lead penetration testing engagements end-to-end: planning, kickoff, testing, documentation, reporting, and follow-up
- Perform and oversee application penetration testing and security vulnerability scanning and provide remediation guidance
- Perform root cause analysis of security issues and deliver actionable remediation guidance
- Create or reproduce and demonstrate POC exploits for findings and externally reported vulnerabilities
- Act as a subject matter expert on penetration testing methodologies, techniques, and procedures
- Build cross-organizational relationships to ensure weaknesses are remediated and lessons learned are captured
- Communicate effectively with stakeholders at all levels, translating technical findings into actionable insights and recommendations
- Report to the Sr. Director of Product Security; work with internal and external stakeholders; role is US-based and fully remote
Requirements
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field
- Minimum 8+ years of, demonstrated, hands-on, experience with internal and external web application, API, and network penetration testing to include writing and reviewing formal penetration test reports, documenting the test details and vulnerabilities, identifying risks, and noting strengths discovered
- Understanding of penetration testing methodology and frameworks (MITRE ATT&CK, OWASP, PTES)
- Understanding of the (S)SDLC (Secure) Software Development Lifecycle
- Skill in illustrating and explaining security vulnerabilities, including proof of concept demonstrations, to audiences with minimal expertise in security
- Experience in the areas of vulnerability identification, malware analysis, and current & emerging exploitation techniques
- Proficiency in source code review, leveraging findings to execute targeted attacks
- Experience with Azure and AWS cloud-based infrastructure
- Certifications preferred: ARTE, eCPPT, eWPT, CARTS, CRTL, CRTO, CRTP, GPEN, GWAPT, OSCP, OSEP, OSWE, Pentest+, PNPT
- Experience working with high security environments subject to regulations such as FedRAMP or ITAR
- Excellent analytical and problem-solving skills with a keen attention to detail
- Experience assisting in CAPEC markups for threat models
- Experience testing Kubernetes and containers