Associate 1, Offensive Security
Core
Perform security assessments, manual penetration testing, and develop remediation recommendations for web applications, network devices, and cloud systems.
Role type
Associate 1, Offensive Security Engineer
Builds
Security assessments and remediation guidance for middle-market clients
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
manual penetration testing, static application security testing (SAST), dynamic application security testing (DAST), web security vulnerability exploitation, secure development practices, cloud security, security standards development, remediation recommendation formulation, technical writing, Python scripting, Ruby scripting, Perl scripting, Docker, CDK, Terraform, Java, React, GraphQL, Javascript, JSON, REST, AWS
Preferred skills
Offensive Security Web Assessor (OSWA), Offensive Security Web Expert (OSWE), Offensive Security Certified Professional (OSCP), Burp Suite Certified Practitioner, AWS Certified Security Specialist
Technologies
Burp Suite, AWS, Docker, CDK, Terraform, Java, Python, React, GraphQL, Javascript, JSON, REST
Responsibilities
Perform security assessments including static and dynamic application security testing, Conduct manual penetration testing on web applications and network devices, Collaborate with clients across various technology stacks and cloud platforms, Develop and interpret security standards and guidance, Demonstrate and promote security best practices including secure development, Assist with developing remediation recommendations for identified findings, Identify and articulate findings to senior management and clients, Help identify improvement opportunities for assigned clients, Stay up-to-date with latest security trends and technologies, Supervise and provide engagement management for other staff
Seniority
Associate 1, hands-on IC