Senior Penetration Testing Associate conducting penetration tests at cybersecurity firm Drawbridge. Collaborating with clients to assess security and improve defenses against cyber threats.
Responsibilities
Conduct internal and external penetration tests across diverse client environments.
Qualify testing requirements and scope engagements with clients.
Troubleshoot and resolve testing issues independently.
Present detailed assessment reports and findings directly to clients.
Consult with clients regarding remediation strategies and best practices.
Act as an escalation point for analysts and associates, providing technical guidance and mentorship.
Manage test scheduling and set client timing expectations to ensure smooth project delivery.
Serve as a technical consulting resource for both internal teams and external clients.
Lead penetration testing efforts against Drawbridge systems and other critical infrastructure.
Perform customized tests for clients, including physical assessments, laptop testing, remote access testing, and cloud environment evaluations.
Create and update relevant internal documentation, ensuring accuracy and completeness.
Develop repeatable and teachable processes for performing various testing tasks.
Assist in improving the organization’s penetration test offerings, including reporting and process enhancements.
Lead breach response discussions and provide advisory services during incident response engagements.
Requirements
5+ years of offensive security experience, with a focus on penetration testing.
Deep knowledge of penetration testing principles, tools, and techniques (e.g., Metasploit, Burp Suite, etc.).
Ability to identify systemic security issues based on vulnerability and configuration analysis.
Experience with Linux and Windows operating systems.
Strong working knowledge of networking concepts and attack stages (footprinting, scanning, enumeration, gaining access, privilege escalation, maintaining access, network exploitation, covering tracks).
Excellent written and verbal communication skills, with the ability to present findings to technical and non-technical audiences.
Strong ability to prioritize, organize, and multi-task in a fast-paced environment.
Experience mentoring junior team members and acting as a technical escalation point.
Excellent written and verbal communication skills.
Excellent time management skills.
Nice if you have experience with IT infrastructure, cloud technology, business continuity, disaster recovery, and incident response.
Knowledge of hedge fund, private equity, or RIA operations/compliance.
Industry certifications (e.g., OSCP, GPEN, CEH).
Experience with Python or comparable scripting language.
Benefits
Competitive compensation package
Employer 401(k) Contribution
Benefits including Medical, Dental, Vision Coverage and Life Insurance
Generous Paid Time Off Policy
Employee Assistance Program (with focus on mindfulness and well-being)
Life Insurance & Personal Accident Insurance
Health Savings Account (HSA) or Flexible Spending Account (FSA)
Security Guard at Las Vegas Ball Park securing the environment and customer service. Providing safety through patrols, incident reporting, and guest assistance in a flexible schedule role.
Security Engineer ensuring secure product development at Aircall, an AI - powered customer communications platform. Collaborating with engineering teams to manage security risks early in the software lifecycle.
IAM Security Engineer working with customers to implement identity management solutions. Collaborating on IAM architecture and best practices for effective access management.
Security Systems Technician role at OPTI SÉCURITÉ specializing in installation and maintenance of electronic security systems. Responsible for supporting customers on - site with security solutions.
Technician for security systems installation and maintenance at OPTI SÉCURITÉ. Responsible for client engagement and technical follow - up on security equipment.
Workday Security Administrator at RSM ensuring secure access across HCM modules and SOX compliance. Leading security design, audits, and stakeholder collaboration with a focus on risk management.
Lead security initiatives across engineering teams as a Senior Technical Program Manager. Overseeing security schedules and compliance to ensure product readiness for release.
Senior IT Security Manager at Creditplus Bank ensuring data confidentiality, integrity, and availability. Leading IT security programs and collaborating in strategic planning and security audits.
Facility Security Officer coordinating sensitive security programs at Booz Allen Hamilton. Ensuring compliance with security policies and conducting briefings while liaising with upper management.
Intermediate Developer in Application Security at Clio, a legal AI leader. Build innovative solutions and collaborate with teams to prevent security vulnerabilities.