Search jobs > Irvine, CA > Senior testing engineer

Senior Penetration Testing Engineer

Capital Group
Irvine, CA, US
$156.9K-$251.1K a year
Full-time

I can succeed as a Senior Penetration Testing Engineer at Capital Group :

As the Senior Penetration Testing Engineer, you are an individual contributor in the Capital Group (CG) AppSec / Penetration Testing team.

The CG AppSec team is part of Information Security in CG’s Information Technology Group. In the role you will be performing web application and network penetration tests, code reviews, security design reviews, red / purple team assessments, and providing security signoffs for technology initiatives.

You will be discovering security issues across web applications, native applications and other systems through threat modeling, code reviews (Java, TypeScript / JavaScript, Python), and dynamic application testing.

As the Senior Penetration Testing Engineer, you will also be responsible for performing red and purple team assessments for Capital Group’s detective security controls.

The team members are geographically dispersed with varying experience levels. As the senior member on the team, you will be creating proof-of-concept exploits for the security issues discovered.

You will be responsible for coordinating and communicating with the key technology stakeholders for delivery of security assessments and explaining technology risks and mitigations.

This role is hybrid (in-office 3 days / week) and can be in Irvine CA, San Antonio TX, or New York NY depending on candidate current location and / or preference.

In addition, you will be responsible for :

Conducting Comprehensive Security Assessments : Perform in-depth penetration tests, infrastructure vulnerability assessments, and application security assessments to identify weaknesses and potential attack vectors.

Executing Tests / Assessments : Plan and execute penetration testing activities using a variety of tools (SAST, DAST, SCA tools) and techniques, including network scanning and web application testing.

Analyzing and Reporting Findings : Analyze test results and prepare detailed reports documenting identified vulnerabilities, their potential impact, and recommended remediation actions.

Collaborating with Stakeholders : Work closely with cross-functional teams across technology, infrastructure, business including developers, system administrators, and business stakeholders, to prioritize and address security findings.

You will be expected to communicate effectively and have an empathetic outlook towards development teams by authoring clear, actionable guidance on writing secure code.

Staying Abreast of Emerging Threats : Keep up to date with the latest security trends, vulnerabilities, and attack techniques to continuously improve testing methodologies and stay ahead of potential threats.

Be an active advocate to software development teams in educating them on secure software development methodologies.

Develop automated proof-of-concepts, and automated security tests by authoring security testing tools.

Execute red and purple team tests of detective tooling including EDR tools, security telemetry tools, anti-virus software, having knowledge of MITRE ATT&CK Framework (Cloud, macOS, Windows, Linux), AI-based software systems.

Develop, organize and lead the Capture-the-Flag (CTF) competitions and be an active participant in such competitions.

I am the person Capital Group is looking for.

You have a bachelor's degree in computer science, a related field, or equivalent experience.

You have a minimum of 5 years of experience in Penetration Testing, Red Team or Application Security

You have a strong understanding of network security, TCP / IP, DNS, TLS, HTTP, IPSec, 802.11, etc.

You have experience with security protocols and / or technologies such as REST APIs, Burp Suite, ZAP, Kali Linux, Windows, macOS, Nmap, Metasploit, Powersploit, Lolbins, etc.

You can automate tasks in Python, bash, Java, C / C# / C++, Rust, etc.

You have a strong understanding of attacks in AWS, Azure, GCP, OAuth, websockets, etc.

You have professional certifications such as Offensive Security Certified Professional (OSCP), OffSec Certified Expert (OSCE) or GIAC Penetration Tester (GPEN) preferred.

Strong knowledge of common security vulnerabilities, attack vectors, and exploitation techniques.

You have excellent communication skills (written, oral), with the ability to simplify and document complex technical details to both technical and non-technical audiences.

You can learn quickly and have a track record of developing a deep understanding of systems and risks to the business.

You have experience coaching and working with engineers to build security and privacy by design.

You have experience performing application design, threat detection, incident response, patching, vulnerability remediation, secure development training, and user training.

You have experience using secure development frameworks (i.e.. OWASP Top 10, SANS Top 25 and Microsoft SDL).

You are proficient in bypassing and tuning security technologies (i.e.. Anti-Malware, IDS, DLP, FIM, Firewalls, SIEM, MFA, Web Proxies and WAF).

You have familiarity with AWS security best practices and Infrastructure-as-Code.

You can work independently, collaboratively and take the initiative to drive security initiatives forward.

You can manage multiple tasks and coordinate / delegate to achieve speedy resolutions to application security-related security incidents working with stakeholders globally.

You have strong analytical and problem-solving abilities, with a keen attention to detail.

Southern California Base Salary Range : $148,045-$236,872

San Antonio Base Salary Range : $121,706-$194,730

New York Base Salary Range : $156,935-$251,096

30+ days ago
Related jobs
Promoted
Capital Group
Irvine, California

As the Senior Penetration Testing Engineer, you are an individual contributor in the Capital Group (CG) AppSec / Penetration Testing team. I can succeed as a Senior Penetration Testing Engineer at Capital Group":. As the Senior Penetration Testing Engineer, you will also be responsible for performin...

Promoted
VirtualVocations
Huntington Beach, California

A company is looking for a Senior Testing & Reliability Engineer to develop and manage testing strategies for product reliability and performance. ...

Promoted
RightStaff, Inc.
Irvine, California

Conduct the vulnerability scanning and penetration testing under the supervision of a Penetration Testing Engineer. Security Engineer (Penetration Testing / Vulnerability Assessment). Check reports on the results of the vulnerability assessment and penetration testing created by another en...

Promoted
Micas Networks
CA, United States

Micas is looking for a top-tier senior network system testing engineer to join Micas networking lab center team. Micas also offers comprehensive data center networking switch development services and custom options, leveraging R&D, engineering, and supply chain management expertise along with high-q...

Capital Group
Irvine, California

As the Senior Penetration Testing Engineer, you are an individual contributor in the Capital Group (CG) AppSec / Penetration Testing team. I can succeed as a Senior Penetration Testing Engineer at Capital Group”:. As the Senior Penetration Testing Engineer, you will also be responsible for performin...

CoStar Group
CA, Orange County

Performs functional, end-to-end, integration, regression, browser and exploratory testing. Designs, documents and implements procedures and techniques that are consistent with departmental SQA Methodology for analyzing, testing, and evaluating risk (software & business), accuracy, completeness, inte...

Anduril
Costa Mesa, California

Function as a member of an interdisciplinary team capable of executing static, dynamic, fatigue, thermal and vibration testing on all of Anduril’s product lines. Be the focal point for instrumentation installation, data acquisition systems, ED shaker operation, and associated equipment for vibration...

Promoted
Intuit
Irvine, California
Remote

As part of this position, you have the opportunity to work 100% remotely, collaborating with an exceptional team from the comfort of your home or office. By providing tax advice, full service return preparation, tax calculations, and managing product/software inquiries, you will be working toward ad...

Promoted
Professional Career Solutions
Santa Ana, California

Remote position (Work from home). Comfortable working remotely and independently. ...

Promoted
Tricon Residential
Tustin, California

This position will be responsible for basic support and working with the engineering team to understand requirements and develop and execute test plans for new software enhancements. Manage and execute the Software Testing Life Cycle (STLS) - requirements analysis, test planning, test case developme...