Conduct Penetration Tests: Perform thorough and methodical penetration testing on web applications, mobile, AI, network infrastructures, and other systems to identify security vulnerabilities.
Vulnerability Assessment: Assess and analyze security weaknesses, and provide actionable recommendations to mitigate risks and improve overall security posture.
Report Findings: Document and communicate findings clearly and effectively to both technical and non-technical stakeholders. Prepare comprehensive reports with recommendations for remediation.
Develop and Execute Test Plans: Design and execute detailed test plans.
Stay Current: Keep up-to-date with the latest security trends, vulnerabilities, and tools to ensure testing methodologies are current and effective.
Collaborate with Teams: Work closely with IT and development teams to understand system architectures, provide guidance on security best practices, and support the implementation of security improvements.
Perform Risk Assessments: Evaluate and assess potential security risks related to new and existing systems and technologies.
Compliance: Ensure that penetration testing practices comply with relevant regulations, standards, and organizational policies.
Participate on projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
Act as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
Requirements
Bachelor's degree preferred
Information security certification / accreditation an asset
7+ years of relevant experience
Expert knowledge of IT security and risk disciplines and practices
Proficiency in penetration testing tools such as Metasploit, Burp Suite, Nmap, and Kali
Knowledge of common web application vulnerabilities (e.g., OWASP Top Ten) and network security principles
Experience with penetration testing in AI, cloud environments (e.g., AWS, Azure) and PCI testing
Familiarity with security standards and frameworks
Relevant certifications such as OSCP, CEH, or GPEN are highly desirable
Benefits
base salary and variable compensation/incentive awards
health and well-being benefits
savings and retirement programs
paid time off (including Vacation PTO, Flex PTO, and Holiday PTO)
banking benefits and discounts
career development
reward and recognition
Job title
Information Security Specialist – Penetration Tester
Junior Quality Engineer collaborating in project teams to maintain compliance with quality standards and regulations. Involving product validation and certification at a well - established IT company.
Quality Engineer responsible for planning and implementing validation strategies at PCI Pharma Services. Collaborating with various teams to ensure compliance and product quality.
Intermediate QA Analyst ensuring data accuracy and quality within Big Data environments. Creating test plans and executing tests while collaborating with data teams.
Technician supporting quality assurance in hardware component testing at GeWeTe. Collaborate on implementing new components and conducting error analyses.
Quality Assurance Analyst overseeing manual and automated testing for quality assurance at MillerKnoll. Leading testing initiatives and collaborating with cross - functional teams for high - quality software solutions.
IT&D Controls Assurance Manager managing a team for IT controls testing lifecycle at Reckitt. Delivering robust testing methodologies meeting SOx standards in healthcare and FMCG industries.
QA Analyst responsible for planning and executing manual and automated tests for EVT. Collaborating with global stakeholders and mentoring in an agile environment in São Paulo.
Manage QA departments ensuring quality in food production at McCormick. Lead regulatory compliance and team development while driving quality standards.