Senior Penetration Testing Analyst
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior penetration tester conducting application or network security assessments for Sophos, a cybersecurity provider. Leading client readiness, exploitation testing, reporting, and remediation discussions.
Responsibilities:
- Coordinate activities, documentation, readiness schedules, and information between business, clients, and project teams
- Act as the point of contact for testing readiness and communicate readiness status
- Use project management tools to monitor tasks, responsible parties, timelines, and status
- Report and escalate issues to management
- Take ownership of new and different requests and identify opportunities to add value
- Conduct application security assessments covering web, mobile, and API security, or network penetration testing assessments
- Use off-the-shelf and internally developed exploitation tools for manual testing and advanced attacks
- Produce and deliver professional security assessment reports containing vulnerability and exploit information
- Lead client conference calls covering readiness, troubleshooting, project kick-off, high/critical finding notifications, and close-out reviews
- Research new threats, vulnerabilities, and exploits
- Conduct exploitation testing and document findings for client remediation
- Work independently and as part of a larger team
Requirements:
- 5+ years of experience in Information Security
- Minimum of 2 years of experience with penetration testing
- Minimum of 2 years of experience with at least one of: Nmap, Metasploit, Kali Linux, Burp Suite
- Excellent client-facing and internal written and verbal communication skills
- Ability to learn quickly and thrive in a high-energy team environment
- Professional, “get it done” attitude, strong work ethic, and team-player approach
- Solid organizational skills, attention to detail, and multitasking skills
- Experience with NMap scanning
- Understanding of web application authentication methods
- Understanding of APIs and API authentication methods
- Understanding of SOAPUI/Restlet and other API testing tools
- Experience with Linux
- Understanding of networking appliances, including routers, load balancers, firewalls, WAF, IDS/IPS, and web content filters/proxies
- Understanding of tools for validating network access with a penetration testing platform
- Applicants must have legal authorization to work in India without employer sponsorship
Benefits:
- Remote-first working model
- Employee-led diversity and inclusion networks
- Annual charity and fundraising initiatives
- Volunteer days
- Global employee sustainability initiatives
- Global fitness and trivia competitions
- Global wellbeing days
- Monthly wellbeing webinars and training
- Recruitment and selection process adjustments for applicants with disabilities or other needs


















