Salary
💰 $87,000 - $151,000 per year
About the role
- Conduct Penetration Tests: Perform thorough and methodical penetration testing on web applications, mobile, AI, network infrastructures, and other systems to identify security vulnerabilities.
- Vulnerability Assessment: Assess and analyze security weaknesses, and provide actionable recommendations to mitigate risks and improve overall security posture.
- Report Findings: Document and communicate findings clearly and effectively to both technical and non-technical stakeholders. Prepare comprehensive reports with recommendations for remediation.
- Develop and Execute Test Plans: Design and execute detailed test plans.
- Stay Current: Keep up-to-date with the latest security trends, vulnerabilities, and tools to ensure testing methodologies are current and effective.
- Collaborate with Teams: Work closely with IT and development teams to understand system architectures, provide guidance on security best practices, and support the implementation of security improvements.
- Perform Risk Assessments: Evaluate and assess potential security risks related to new and existing systems and technologies.
- Compliance: Ensure that penetration testing practices comply with relevant regulations, standards, and organizational policies.
- Participate on projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
- Act as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
Requirements
- Bachelor's degree preferred
- Information security certification / accreditation an asset
- 7+ years of relevant experience
- Expert knowledge of IT security and risk disciplines and practices
- Proficiency in penetration testing tools such as Metasploit, Burp Suite, Nmap, and Kali
- Knowledge of common web application vulnerabilities (e.g., OWASP Top Ten) and network security principles
- Experience with penetration testing in AI, cloud environments (e.g., AWS, Azure) and PCI testing
- Familiarity with security standards and frameworks
- Relevant certifications such as OSCP, CEH, or GPEN are highly desirable