Ethical Hacker / Penetration Tester
Job Description
Work fully remote from Michigan or Illinois while supporting a credit union cybersecurity program focused on finding, fixing, and preventing real-world vulnerabilities. You will conduct comprehensive offensive security assessments across multiple environments and help strengthen security awareness through phishing simulation and threat-focused training. MSU Federal Credit Union also offers robust coverage and time off, including 100% company-paid health, dental, vision, life, and long-term disability premiums, up to 26 days of PTO in your first year, and up to 12 weeks of paid parental leave.
What you’ll do
- Conduct network penetration tests, web application security assessments, mobile application security assessments, and wireless network assessments, along with red team assessments and phishing tests within scheduled time frames using industry best practice methodologies.
- Identify and document security issues and recommendations using independent judgment across reviewed areas.
- Present findings through written reports and oral presentations to Credit Union leadership, including the President/CEO and the Board of Directors.
- Perform security assessments of third-party applications used by the Credit Union within scheduled time frames.
- Stay current on emerging cybersecurity trends, tools, and techniques to continuously improve testing methodologies and security practices.
- Assist with coordinating and performing contracted penetration testing projects and services delivered by third-party vendors.
- Evaluate risk areas and provide key input into the development of the annual penetration testing plan.
- Support security awareness by administering phishing simulation and participating in best practice and emerging threat training sessions.
- Understand and follow Credit Union policies and procedures, adhering to internal controls to safeguard assets, prevent fraud, and maintain the integrity of credit union operations.
- Develop, implement, and refine advanced penetration testing techniques and apply ethical hacking tools in an innovative and comprehensive manner.
- Seek out new risk opportunities, assess emerging threats and vulnerabilities, and contribute security and control insights to strategic and innovative projects.
Requirements
- High School Diploma or equivalent required.
- Bachelor’s degree (or equivalent experience) in computer science, information technology, or a related field.
- Required prior experience in penetration testing, vulnerability assessments, or related security testing activities.
- Experience leading a program or independently managing offensive security operations in professional penetration testing and/or vulnerability assessment.
- GIAC GPEN or GIAC GWAPT (or pursuing similar designation) is required.
- GIAC GPEN, GIAC GWAPT, or pursuit of similar designation is preferred.
Tools & technologies
GIAC GPEN, GIAC GWAPT
Schedule & work arrangement
- Monday - Friday, 8:30am - 5:00pm ET
- Fully remote role within the state of Michigan or Illinois
Benefits
- 100% Company-Paid Health, Dental, Vision, Life, and Long-Term Disability premiums
- Up to 26 days of PTO within your first year, plus Volunteer Time Off and 11 paid holidays
- 401(k) with a company match
- Tuition reimbursement
- Up to 12 weeks of paid parental leave
- Learn more: https://www.msufcu.org/benefits
Competencies: Communicate; Navigate Change & Evolve; Solve Problems & Make Decisions; Plan, Prioritize, and Achieve; Collaborate. Also includes Digital Literacy, Time Management, Critical Thinking, Initiative, Knowledge Sharing, Organization, System Knowledge, Detail Oriented, Resourcefulness, and Process Improvement.
Physical demands & environment: May require extended stationary work; ability to operate standard office technology with many hours of computer and phone usage; occasional movement inside an office. Exposure to potentially hazardous conditions may occur (for example, robbery), with detailed instructions and procedures provided to minimize exposure. This position can work in hybrid or remote working arrangements.
Important note: This job description is not exhaustive and does not represent a contract. MSU Federal Credit Union may change the position description or assign tasks as needed. Reasonable accommodations may be made for qualified individuals with disabilities. MSUFCU is an affirmative-action, equal-opportunity employer.
Offer contingency: An offer is contingent upon the agreed work arrangement. MSU Federal Credit Union may or may not be able to accommodate temporary or permanent changes to work arrangements or allow employment outside the city and/or state of residency at the time of hire.