Penetration Tester
Job Description
Philadelphia Comapny is hiring a Penetration Tester in Atlanta, GA with remote flexibility. This role validates security controls through penetration testing across the organization, while also delivering security consulting and advisory in a risk-based framework. You will evaluate security posture, surface risks, and outline remediation plans spanning applications, networks, platforms/OS security, and biomedical devices.
Responsibilities
- Apply a risk-based approach to balance security and business priorities while validating security controls through penetration tests across the organization
- Perform information security penetration tests
- Provide security consulting and advisory across one or more areas, including application, network, platform/OS security, and biomedical devices
- Assess the security posture of existing environments
- Identify risks and document findings
- Recommend remediation plans to address identified deficiencies
- After successfully completing penetration testing, help strategize and architect security solutions to remediate gaps
- Collaborate directly with project personnel, business application owners, and management teams
- Articulate information security requirements and risks in business language that can be understood by non-technical stakeholders
Requirements
- Excellent analytical skills alongside strong written and verbal communication
- Strong interpersonal, motivational, organizational, persuasive, and project management skills
- Proven ability to work effectively with management, staff, vendors, and external consultants
- Ability to think creatively and conduct pentests on applications, systems, and network using proven or formal processes and industry standards
- In-depth understanding of emerging threats and vulnerabilities, including how they may be exploited
- Ability to manage multiple pentest engagements from start to completion at the same time
- Understanding of security risk assessment methodologies
- Ability to assess both technical and business risks related to information security
- Good understanding of the regulatory climate and industry standards such as SOX, HIPAA, and PCI
- Ability to translate complex technical concepts for non-technical audiences, tailor communication to stakeholders, and facilitate discussions between others
- Ability to gain stakeholder buy-in to resolve significant architecture issues
- Demonstrated ability to lead technical teams across functional areas or with the “client,” and lead technology direction at the highest solution architectural level
- Experience building up a solutions architecture team
- Ability to transfer knowledge through education and mentoring in area(s) of expertise
- Demonstrated ability in selection and deployment of new and emerging technology
Basic Qualifications
- Bachelor’s degree in Information Systems, Computer Science, Engineering, Mathematics and/or a minimum of 4 years of equivalent work experience
- Minimum of 3 years of experience in Information Technology and/or Technology Consulting
- Minimum of 3 years demonstrated ability in two or more of: application security, network security, or platform/OS security in engineering, architecture, or consulting capacity (consulting background preferred)
- Minimum of 2 years of penetration testing or ethical hacking for a consultancy or a large enterprise
- Ability to synthesize and abstract complex data to lead complex decision processes and produce strategic solutions that improve competitiveness with timely, cost-effective, high-quality outcomes
- Excellent verbal and written communication skills, including the ability to tailor communication to the audience and communicate architecture to management and customers
- Ability to gain buy-in from stakeholders to resolve significant architecture issues
- Demonstrated ability to lead technical teams, build up a solutions architecture team, and mentor other staff
- Ability to transfer knowledge and educate others in area(s) of expertise
- Demonstrated ability in selection and deployment of new and emerging technology
Additional information: all information provided will be kept confidential according to EEO guidelines.