Senior Security Specialist
Core
Senior penetration testing SME overseeing security testing engagements across applications, infrastructure, cloud, and networks to deliver risk reduction and technical assurance.
Role type
Senior IC security testing specialist (penetration testing SME)
Builds
Security testing engagements, risk mitigation solutions, and internal security testing tools
Domain
Financial services / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing (Web Apps, APIs, Thick Client, infrastructure), Application security, Network protocols, Cloud environments (AWS, Azure, GCP), Containerization (Docker, Kubernetes), Vulnerability reporting, Risk assessment, Vendor management, Testing standards (OWASP, PTES), Tooling (Burp Suite)
Preferred skills
Threat modelling, Large regulated enterprise experience, Certifications (OSCP, GPEN, GWAPT, CREST)
Technologies
Burp Suite, AWS, Azure, GCP, Docker, Kubernetes
Responsibilities
Oversee penetration testing engagements from scoping to delivery; Review testing methodologies, attack paths, and reports to ensure quality; Manage third-party testing vendors; Advise on remediation and risk acceptance; Drive practice improvement and tool development; Translate technical findings for stakeholders
Seniority
Senior, hands-on IC with mentorship responsibilities