The Job logo

What

Where

Cybersecurity Engineer - Penetration Tester

ApplyJoin for More Updates

You must Sign In before continuing to the company website to apply.

Smart SummaryPowered by Roshi
Join cxLoyalty as our In-House Penetration Testing professional! You'll be responsible for protecting our business operations, clients, and data from vulnerabilities and security breaches. As a key member of our Threat and Vulnerability Management team, you'll plan, coordinate, and manage global penetration tests, conduct network testing of cloud systems, and provide expert recommendations to mitigate security risks. If you have a strong understanding of infrastructure/cloud architecture, experience in pen testing, and a willingness to travel, we want to hear from you!

As part of the Threat and Vulnerability Management operations arm, your role is pivotal in protecting the cxLoyalty’s business operations, clients and employees’ data and the organizations intellectual property. This job is for an In-House Penetration Testing professional. They should be proficient in cloud vulnerability assessments, penetration testing, and professionally relaying technical vulnerabilities and their impact to technical and non-technical customers. A successful candidate will be able to demonstrate knowledge of general Cybersecurity infrastructure and cloud principles. Ideally, they will understand program and project level delivery processes for penetration testing in large scale organizations. This position will not be solely working as a penetration tester as the aim is to partner with other teams to drive real solutions while maintaining independence. Assessments delivered would be primarily [80-90%] remote with some [10-20%] at an onsite location. They should be comfortable identifying vulnerabilities using manual and automated tools of the trade but not have to rely on automation. They should be comfortable manually exploiting vulnerabilities, performing post-exploitation activities, and explaining the path to compromise to external and internal stakeholders.

Responsibilities:

  • Plan, scope, coordinate, and manage penetration tests on a global level from initiation to closure
  • Carry out remote/onsite network testing of the cloud to expose weaknesses in security
  • Plan, create and execute penetration attack methods, scripts, and tests using the current polices and process
  • Simulate security breaches to test a system's relative security
  • Work with the business to determine test requirements 
  • Understand how identified flaws could affect a business, or business function, if they're not fixed.
  • Create reports and recommendations from findings
  • Collaborate with other teams to act as an advisor on methods to fix or lower security risks

Qualifications:

The candidate will need a strong understanding of infrastructure/cloud architecture and security testing approaches. This will include using tools, manual testing, and various testing techniques. 

  • Demonstrated continued technical growth (Where are you getting CPE’s?)
  • Ability to independently conduct and lead security assessments 
  • Ability to script and understand basic coding
  • Ability to represent/convey information, both verbal/written to multiple organization levels (Social intelligence)
  • Ability to explain/convey technical vulnerabilities to technical/non-technical 3rd parties. (Technical Intelligence)
  • Understand complex computer systems and technical cyber security terms as well as their applications

Requirements:

To be considered for this position, these are the minimum requirements:

  • At least one of the following Certification(s): OSCP/OSWP/OSCE/OSEE/OSWE/OSEP/CEH and CISSP/CISM
  • 3+ years of ‘fingers on keyboard’ experience in Penetration testing and vulnerability assessment
  • 3+ years of server, application, and network security hardening experience (e.g. design, recommend and implement security hardening technical controls)
  • 3+ years in Information Technology Infrastructure 
  • 1+ years of experience working in a public cloud environment (e.g. AWS, GCP or Azure)
  • Ability to manually conduct a penetration test
  • Proficient in coding in one of more languages (e.g.  Python, Bash, Java, C++, PowerShell…)
  • Overall knowledge of the Software Development Life Cycle
  • Willingness to travel up to 20%
Set alert for similar jobsCybersecurity Engineer - Penetration Tester role in Plano, United States, Wilmington, United States, or Columbus, United States
JPMorgan Chase & Co. Logo

Company

JPMorgan Chase & Co.

Job Posted

a year ago

Job Type

Full-time

WorkMode

Hybrid

Experience Level

3-7 Years

Category

Cyber Security

Locations

Plano, Texas, United States

Wilmington, Delaware, United States

Columbus, Ohio, United States

Qualification

Bachelor

Applicants

Be an early applicant

Related Jobs

JPMorgan Chase & Co. Logo

Software Engineer III - HCM Security

JPMorgan Chase & Co.

Columbus, Ohio, United States

+1 more

Posted: a year ago

The HCM Security Software Engineer is responsible for providing technical support, security architecture, and security assurance services on the firm's HCM platform. They will manage Oracle HCM implementations, support modules in production, and work on creative security solutions. Key responsibilities include configuration, defect resolution, and developing secure production code. The engineer will also collaborate with stakeholders to understand security needs and minimize vulnerabilities. They will contribute to a diverse and inclusive team culture.