Staff Cybersecurity Engineer - Pen Testing
The Staff Specialist Cybersecurity Engineer is responsible for identifying, assessing, and helping mitigate cybersecurity risks across the organization's infrastructure, applications, cloud environments, and external attack surface. This role combines hands-on penetration testing with broader threat management responsibilities, vulnerability risk assessment, attack surface monitoring, threat intelligence analysis, and security validation activities.
The ideal candidate possesses strong offensive security skills, practical experience conducting infrastructure and application penetration tests, and the ability to translate technical findings into actionable risk reduction strategies for engineering and business stakeholders. Experience with autonomous and LLM assisted penetration testing is desired.
Key Responsibilities:
- Penetration Testing and Security Assessments
- Perform infrastructure penetration testing across internal, external, cloud, and hybrid environments.
- Conduct web application and API security assessments.
- Perform adversary emulation and attack path validation to identify exploitable weaknesses.
- Execute authenticated and unauthenticated security assessments of operating systems, databases, network devices, and security technologies.
- Validate vulnerability exploitability and determine real-world business risk.
- Develop detailed technical reports and executive summaries documenting findings, attack paths, and remediation recommendations.
- Partner with support and infrastructure teams to validate remediation efforts and conduct retesting activities.
Threat Management:
- Identify, assess, and prioritize emerging threats that may impact the organization.
- Analyze threat intelligence from commercial, open-source, and industry sources.
- Support continuous attack surface management initiatives to identify exposed assets and security risks.
- Conduct risk-based analysis of vulnerabilities and provide prioritization guidance based on exploitability and business impact.
- Assist in developing and maintaining threat management processes, standards, and reporting.
Required Skills:
- 5+ years of experience in cybersecurity or information technology security role, with specialization in cyber threat intelligence and penetration testing.
- Candidates must be familiar with vulnerability attributes like CVEs, CVSS, and threat detection and hunting frameworks like MITRE ATT&CK framework.
- Strong understanding of network services, vulnerabilities, and attacks. Knowledge of application exploits and vulnerabilities. Knowledge of ports and services typical in the configuration of web servers, file servers, and workstations
- Previous experience conducting penetration testing both using autonomous and AI tools and manually using experience and infrastructure knowledge.
- Strong written, communication, and presentation skills along with the ability to work in a highly collaborative environment
Desired skills (nice to have):
- Well-developed scripting skills in Python or PowerShell.
- Strong knowledge of web and application security, good working knowledge of cloud security as it applies to Threat Management.
- Broadly experienced Cybersecurity Engineer with depth of knowledge in two or more disciplines.