Responsibilities
- Perform hybrid web application penetration tests combining source code review with runtime exploitation on products and internal tools.
- Conduct external network penetration tests against internet-facing systems to identify exposed services, misconfigurations, and initial access vectors.
- Execute internal network and Active Directory security assessments to find privilege escalation paths, lateral movement opportunities, and misconfigurations.
- Evaluate security of cloud and containerized environments, including identity, network, and workload configurations.
- Work with detection engineering to validate telemetry and detection coverage against real-world attack techniques discovered during engagements.
- Manage third-party penetration testing engagements from scoping to completion, critically review results, and collaborate across teams to prioritize and implement fixes.
- Partner with engineering teams to reproduce, prioritize, and verify remediation of identified issues.
- Design and develop offensive security tools and automation tailored to the company's technology stack.
- Create clear, actionable reports and presentations for both technical and non-technical audiences, translating findings into business risk and prioritized actions.
Benefits
- Medical, dental, and vision insurance, plus voluntary life insurance for employees and eligible dependents.
- Automatic coverage under basic life, AD&D, and disability insurance.
- Commuter benefits.
- Relocation assistance.
- Take what you need paid time off, not based on accrual.
- Two weeks of paid time off at the end of each year, subject to team and business needs.
- Ten paid holidays per calendar year.
- Supportive leave of absence program, including time off for military service and medical events.
- Paid leave for new parents and subsidized backup care for all parents.
- Fertility and family building benefits, including adoption, surrogacy, and preservation.
- Stipend to assist with expenses related to a new child.
- Eligibility to enroll in the company's 401k plan.
Work Arrangement
On-site
Other
Willingness and eligibility to obtain a U.S. security clearance preferred.