Talent.com
Principal, Cybersecurity Penetration Tester

Principal, Cybersecurity Penetration Tester

Fidelity Investments Inc.Boston, MA, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Job Description :

The mission of the penetration testing team is to protect Fidelity's assets and our customers’ livelihoods from the threat of exploitation by malicious adversaries. The penetration testing team does this by proactively identifying vulnerabilities in our systems and serving as subject matter experts to enable the business units to mitigate them in a positive, collaborative, innovative manner.

Lead testing efforts on Fidelity's web and mobile applications and supporting systems.

Replicate the actual techniques and tools used by malicious attackers in an effort to model potential external threats.

Upon completion of the assessment, you will prepare reports and present the results to application owners, developers, and business unit information security teams.

Analyze test results, draw conclusions from results, and develop targeted exploit examples.

Consult with operations and software development teams to ensure potential weaknesses are addressed.

Contribute to the research or development of tools to assist in the vulnerability discovery process.

Collaborate with other teams within Enterprise Cybersecurity to improve the overall security of Fidelity's applications and infrastructure.

Stay current on security best practices and vulnerabilities.

The Expertise You Have and The Skills You Bring

Bachelors degree or equivalent experience

5+ years of IT experience

Preferred 3+ years of hands-on web application penetration testing / ethical hacking experience

Preferred : OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.

Ability to demonstrate manual testing experience including all of OWASP Top 10

Intermediate knowledge of application security mechanisms such as authentication and authorization techniques, data validation, and the proper use of encryption

Technical knowledge of, and the ability to recognize, various types of application security vulnerabilities.

Demonstrated experience with common penetration testing and vulnerability assessment tools such as nmap, Wireshark, Nessus, NeXpose, BackTrack, Metasploit, AppScan, WebInspect, Burp Suite Professional, Acunetix, Arachni, w3af, NTOSpider

Intermediate knowledge of a programming or scripting language such a C, C#, Python, Objective C, Java, Javascript, SQL,

Intermediate knowledge of Web Services technologies such as XML, JSON, SOAP, REST, and AJAX

Intermediate knowledge of web frameworks, including XML, SOAP, J2EE, JSON and AJAX

Experience with Enterprise Java or .NET web application frameworks, including Struts and Spring

Proven analytical and problem-solving skills, as well as the desire to assist others in solving issues

Excellent interpersonal skills with a strong interest in the application security domain

Excellent communication and presentation skills and a proven ability to communicate threats and facilitate progress towards long-term remediation.

Highly motivated with the willingness to take ownership / responsibility for their work and the ability to work alone or as part of a team.

The Team

The Penetration Testing team forms part of Security Assessment group within Enterprise Cybersecurity (ECS). The goal of the Security Assessment group is to proactively identify and remediate vulnerabilities in Fidelity’s applications and infrastructure. We work very closely with all of the key Business Units to ensure that they remain secure while they deliver key projects to advance the firm.

Certifications : Category :

Information Technology

Fidelity’s hybrid working model blends the best of both onsite and offsite work experiences. Working onsite is important for our business strategy and our culture. We also value the benefits that working offsite offers associates. Most hybrid roles require associates to work onsite every other week (all business days, M-F) in a Fidelity office.

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and / or associating with individuals with certain Criminal Histories.

#J-18808-Ljbffr

serp_jobs.job_alerts.create_a_job

Penetration Tester • Boston, MA, United States

Job_description.internal_linking.related_jobs
  • serp_jobs.job_card.promoted
Border Patrol Agent

Border Patrol Agent

U.S. Customs and Border ProtectionNorth Scituate, MA, United States
serp_jobs.job_card.full_time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Principal Cyber Tool and Capability Developer

Principal Cyber Tool and Capability Developer

Draper LabsCambridge, MA, United States
serp_jobs.job_card.full_time
Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA.The 2,000+ employees of Draper tackle important national challenges with a promise of delivering ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Fraud Manager, PINS

Fraud Manager, PINS

Zelis Healthcare, LLCBoston, MA, United States
serp_jobs.job_card.full_time
Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers.We serve more than 750 payers, including the top five national health plans, regional hea...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Remote Product Tester – $45 / hr + Free Products – Start Now!

Remote Product Tester – $45 / hr + Free Products – Start Now!

OCPAPembroke, Massachusetts, us
serp_jobs.filters.remote
serp_jobs.job_card.part_time +1
Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. We guarantee 15-25 hours per week with an hourly pay of bet...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Principal Cyber Security Engineer

Principal Cyber Security Engineer

RaftHanscom Air Force Base, MA, United States
serp_jobs.job_card.full_time
All of the programs we support require.All work must be conducted within the continental U.Distributed Data Systems, Platforms at Scale, and Complex Application Development, with headquarters in Mc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Advanced Security Engineer - Cyber Security

Advanced Security Engineer - Cyber Security

RelativityBoston, MA, United States
serp_jobs.job_card.full_time
As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Customs and Border Protection Officer - Experienced (GS9)

Customs and Border Protection Officer - Experienced (GS9)

U.S. Customs and Border ProtectionNorth Scituate, MA, United States
serp_jobs.job_card.full_time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Lead, Systems Engineer (Cost Engineer - TruePlanning))

Lead, Systems Engineer (Cost Engineer - TruePlanning))

L3Harris TechnologiesGLOUCESTER, Massachusetts, United States
serp_jobs.job_card.full_time
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers’ mission and quest ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Cyber Security Analyst

Cyber Security Analyst

VirtualVocationsLowell, Massachusetts, United States
serp_jobs.job_card.full_time
A company is looking for a Cyber Security Analyst I.Key Responsibilities Pursue skills in the standard intelligence cycle including collection, analysis, and dissemination on various topics Rese...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Sales Representative (Remote)

Sales Representative (Remote)

American Income LifeGloucester, MA, US
serp_jobs.filters.remote
serp_jobs.job_card.full_time
A Sales Career That Grows With You.Are you looking for a career path that gives you the freedom and flexibility to control your schedule, but also has the security and stability of a large company?...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Cybersecurity SME

Cybersecurity SME

AvintNorth Lexington, MA, US
serp_jobs.job_card.full_time
Applicants must have an Active Top Secret Clearance • •.The Cybersecurity SME serves as a cybersecurity and RMF expert within the technical domain and acts as a senior advisor to government cybersecu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Lead Security Engineer - Cyber Security

Lead Security Engineer - Cyber Security

RelativityBoston, MA, United States
serp_jobs.job_card.full_time
As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Senior Full Stack Engineer

Senior Full Stack Engineer

VirtualVocationsLowell, Massachusetts, United States
serp_jobs.job_card.full_time
A company is looking for a Senior Full Stack Engineer for a remote position focused on developing AI governance products. Key Responsibilities Build AI governance and enforcement features such as ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Remote Finance Director - AI Trainer

Remote Finance Director - AI Trainer

Data AnnotationPeabody, Massachusetts
serp_jobs.filters.remote
serp_jobs.job_card.full_time +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the q...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Border Patrol Agent - Experienced (GL9 / GS11)

Border Patrol Agent - Experienced (GL9 / GS11)

U.S. Customs and Border ProtectionNorth Scituate, MA, United States
serp_jobs.job_card.full_time
Check out these higher-salaried federal law enforcement opportunities with the U.Your current or prior law enforcement experience may qualify you for this career opportunity with the nation's premi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Senior Product Compliance Engineer

Senior Product Compliance Engineer

EntegrisBillerica, MA, United States
serp_jobs.job_card.full_time
Senior Product Compliance Engineer.Not everyone who works for a global company shares the same background, experiences and perspectives. We leverage the differences of our employees to bring new ide...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Principal Systems Engineer

Principal Systems Engineer

Digital Health SolutionsAndover, MA, US
serp_jobs.job_card.full_time
Digital Health Solutions (DHS) is a premier consulting firm dedicated to advancing medical device innovation.We partner with companies across the medical technology spectrum to deliver safe, effect...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Security Lead

Security Lead

VirtualVocationsLowell, Massachusetts, United States
serp_jobs.job_card.full_time
A company is looking for a Security Lead to build and manage its security function across governance, engineering, and operations. Key Responsibilities Own the company's security posture from code...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30