Senior Associate, Offensive Security
Core
Conduct manual and automated application security testing to identify vulnerabilities in client web applications, network devices, and cloud systems.
Role type
Senior IC application penetration tester
Builds
Security assessments and remediation guidance for client application portfolios
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
manual penetration testing, static application security testing (SAST), dynamic application security testing (DAST), web security exploitation, cloud security, secure development practices, remediation strategy, technical writing, team supervision
Preferred skills
Offensive Security certifications (OSWA, OSWE, OSCP), Burp Suite Certified Practitioner, AWS Certified Security Specialist
Technologies
Java, Python, Ruby, JavaScript, AWS, Docker, CDK, Terraform, React, GraphQL, JSON, REST
Responsibilities
Supervise and lead security assessments including SAST and DAST; conduct manual penetration testing on web apps and network devices; collaborate with clients across various technology stacks; develop and interpret security standards; demonstrate security best practices; assist in developing remediation recommendations; articulate findings to senior management and clients; mentor and manage engagement staff
Seniority
Senior, hands-on IC with mentorship duties