Salary
💰 $135,000 - $143,000 per year
Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud PlatformIoTPython
About the role
- Plan and lead penetration testing engagements across networks, applications, cloud infrastructure, APIs, and mobile platforms
- Focus area on technical project leadership and cloud penetration testing engagements
- Deliver clear, actionable technical reports and executive summaries
- Provide expert guidance on remediation and risk mitigation strategies
- Collaborate cross-functionally with delivery teams, project managers, and sales to ensure successful engagement outcomes
- Escalate critical issues and ensure timely resolution of project challenges
- Mentor and support the development of less experienced team members
- Contribute to research, tool development, and knowledge sharing within the security practice
- Support the achievement of team utilization and delivery metrics
Requirements
- Bachelor's degree (four-year college or university) or equivalent combination of education and work experience
- Minimum 5+ years of hands-on experience in network and/or application penetration testing
- Minimum 5+ years of experience in cybersecurity consulting
- Demonstrated expertise in one or more areas: Web Application, API, Mobile, Cloud, and Internal and External Network Penetration Testing
- Proficiency in multiple scripting or programming languages (e.g., Python, PowerShell, C, Bash)
- Experience testing against one or more IT security compliance frameworks, such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST
- Strong understanding of security frameworks and standards (e.g., OWASP, NIST, PTES, PCI DSS, HIPAA, FedRAMP)
- Proven experience interacting with clients, delivering presentations, and writing detailed assessment reports
- Experience leading penetration testing engagements and working independently in a client-facing capacity
- Willingness to travel occasionally (up to 10%)
- Solid proficiency in at least one of the following areas: Compliance-Driven Penetration Testing (e.g., PCI, FedRAMP); Cloud Penetration Testing (e.g., AWS, Azure, GCP); Network/Active Directory Penetration Testing; Application (Web/API/Mobile/Thick) Penetration Testing; Secure Code Review; Hardware or IoT Testing; Container Security Testing; AI or ML System Testing