Search jobs > New York, NY > Part-time > Penetration tester

Principal Security Penetration Tester, Cyber Solutions

DaVita Inc.
New York, New York, US
$130K-$180K a year
Full-time
Part-time

The Proactive Security Testing team is looking for motivated individuals to add to its team. We provide a challenging and exciting work environment that offers a healthy combination of autonomy and senior level support.

Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and is engaged in a variety of continuous security research projects.

Have you got what it takes to succeed The following information should be read carefully by all candidates.

Aon is in the business of better decisions.

At Aon, we shape decisions for the better to protect and enrich the lives of people around the world. As an organization, we are united through trust as one inclusive, diverse team, and we are passionate about helping our colleagues and clients succeed.

What the day will look like

As a Principal Security Penetration Tester (termed internally as a "Security Testing Manager"), you will serve as a senior member of the penetration testing team.

In addition, the person in the role will do the following :

  • Perform penetration testing activities focused on assessing the security of web applications, mobile applications, APIs, and thick clients.
  • Conduct complex hybrid web application security assessments, involving code review and dynamic application testing applying a combination of static and dynamic source code analysis techniques.
  • Perform infrastructure penetration testing, including external / internal penetration testing, red teams, etc.
  • Write test harnesses to help identify and proof-of-concept potential security vulnerabilities.
  • Clearly communicate vulnerabilities to client development teams during and post-assessment.
  • Document technical issues identified during security assessments, outlining the associated risks for clients, and providing tailored recommendations for remediation.
  • Assist colleagues in pre-sales scoping activities for penetration testing engagements.
  • Offer technical mentorship and career development guidance to junior engineers within the organization.
  • Engage in vulnerability research to produce blog posts, conference talks, whitepapers, etc.
  • Contribute to internal business operations by participating in and suggesting process improvements.
  • Develop, update, and improve internal tooling used for reporting and penetration testing.
  • Partner with the team in the recruitment of new penetration testing talent including reviewing resumes and conducting interviews.

Skills and experience that will lead to success.

  • 5+ years of hands-on penetration testing and / or bug bounty experience against web / mobile applications, above and beyond running automated tools.
  • 5+ years of hands-on experience performing network / infrastructure penetration testing.
  • Some expertise in development and / or source code review, focusing on languages such as Java, C#, C / C++, PHP, Ruby, Python, Go, Swift, Objective C / C++, Kotlin, etc.
  • Up to date experience with testing techniques and tooling, such as Burp Suite and other fuzzers / proxies.
  • Up to date experience with code review scanning tools, such as Fortify, Semgrep, etc.
  • Deep knowledge of common software vulnerabilities, such as those described in the OWASP Top 10 and CWE / SANS Top 25.
  • Possesses a solid grasp of Unix, Windows, and network security.
  • Ability to work remotely as part of a distributed team and travel to client sites when required.
  • Excellent communication skills (written & verbal) in English, to present complex technical topics concisely to both technical and business audiences.

We do not offer visa sponsorship for this role.

How we support our colleagues

In addition to our comprehensive benefits package, we encourage a diverse workforce. Plus, our agile, inclusive environment allows you to manage your wellbeing and work / life balance, ensuring you can be your best self at Aon.

Furthermore, all colleagues enjoy two "Global Wellbeing Days" each year, encouraging you to take time to focus on yourself.

We offer a variety of working style solutions, but we also recognize that flexibility goes beyond just the place of work.

and we are all for it. We call this Smart Working!

Our continuous learning culture inspires and equips you to learn, share and grow, helping you achieve your fullest potential.

As a result, at Aon, you are more connected, more relevant, and more valued.

Aon values an innovative, diverse workplace where all colleagues feel empowered to be their authentic selves. Aon is proud to be an equal opportunity workplace.

Aon provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran, marital, domestic partner status, or other legally protected status.

People with criminal histories are encouraged to apply.

We welcome applications from all and provide individuals with disabilities with reasonable adjustments to participate in the job application, interview process and to perform essential job functions once onboard.

If you would like to learn more about the reasonable accommodations we provide, email [email protected]

For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.

Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.

Pay Transparency Laws :

The salary range for this position (intended for U.S. applicants) is $130,000 - $180,000 annually. The actual salary will vary based on applicant's education, experience, skills, and abilities, as well as internal equity and alignment with market data.

The salary may also be adjusted based on applicant's geographic location.

This position is eligible to participate in one of Aon's annual incentive plans to receive an annual discretionary bonus in addition to base salary.

The amount of any bonus varies and is subject to the terms and conditions of the applicable incentive plan.

  • Aon offers a comprehensive package of benefits for full-time and regular part-time colleagues, including, but not limited to : a 401(k) savings plan with employer contributions;
  • an employee stock purchase plan; consideration for long-term incentive awards at Aon's discretion; medical, dental and vision insurance, various types of leaves of absence, paid time off, including 12 paid holidays throughout the calendar year, 15 days of paid vacation per year, paid sick leave as provided under state and local paid sick leave laws, short-term disability and optional long-term disability, health savings account, health care and dependent care reimbursement accounts, employee and dependent life insurance and supplemental life and AD&D insurance;

optional personal insurance policies, adoption assistance, tuition assistance, commuter benefits, and an employee assistance program that includes free counseling sessions.

Eligibility for benefits is governed by the applicable plan documents and policies.

LI-KH1

2024-82301

J-18808-Ljbffr

3 days ago
Related jobs
Promoted
Jobs via eFinancialCareers
New York, New York

As a Principal Security Penetration Tester (termed internally as a “Security Testing Manager”), you will serve as a senior member of the penetration testing team. Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and is engaged in a...

Promoted
DaVita Inc.
New York, New York

As a Principal Security Penetration Tester (termed internally as a "Security Testing Manager"), you will serve as a senior member of the penetration testing team. Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and is engaged in a...

Promoted
Aon Hewitt
New York, New York

As a Principal Security Penetration Tester (termed internally as a “Security Testing Manager”), you will serve as a senior member of the penetration testing team. Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and are engaged in ...

Promoted
TikTok
New York, New York

As an Application Security Penetration Tester, you will validate security controls around web resources and mobile applications and their backend web services for TikTok. All Application Security Penetration Testers are expected to continuously improve their tradecraft through research, to add bread...

Promoted
Capgemini Government Solutions
New York, New York

This position is also a leader with vision in the practice of Big Data in solving our clients’ cyber security problems, coupled with Proven experience in developing enterprise data solutions for large clients through innovative ways, effective communication of white papers, and other solutions. Capg...

Promoted
Stratford Solutions Inc.
New York, New York

Cloud Cybersecurity efforts and emerging technology aligned with the Risk Management Framework (RMF). Using technical IT tools and IT software to monitor, analyze, and defend against cyberattacks. Investigating security incidents, identifying root causes, and implementing corrective actions to preve...

Capital One
New York, New York

Professional Certification (Security+, Data+, Cyber Security Analyst+, or Systems Security Certified Practitioner). Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Security Data Scientist. Cyber Data Science (CDS) is looking for a data-focused professional with...

Stratford Solutions Inc.
New York, New York

The Contractor/cybersecurity analyst would perform a variety of services, both in-person at NYC Health Department locations and, if needed, remotely, including but not limited to:. The contractor/cybersecurity analyst would have the following credentials, organizational capability, and/or experience...

Capital One
New York, New York

Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. Offensive Security is part of the Cyber Operations and Intelligence program and assists with ident...

Shackleton Duke Group
New York, US

A leading, global managed services and professional security consultancy organisation has identified a business critical opportunity out of NYC, for an experienced Digital Solutions Architect. Harvest client solutions to implement reference architectures and define reusable solutions. The Digital So...