Security Assurance Penetration Tester
Job Description
Based onsite in Pennsylvania, this security role sits within Elsevier’s Security Engineering team. The position offers a yearly salary range of USD 71,600 to 119,400 and focuses on hands-on security testing, vulnerability validation, and security control verification, with particular emphasis on GenAI security testing across LLMs, RAG pipelines, and AI agents in collaboration with development teams.
Responsibilities
- Track and triage findings from third-party assessments, ensuring timely follow-up and remediation tracking.
- Collaborate with development, platform, and product teams to communicate findings, monitor remediation efforts, and strengthen overall security posture.
- Lead post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
- Maintain program documentation, test records, and reporting artifacts.
- Conduct penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
- Perform peer review of penetration testing deliverables, including test plans, findings, and final reports.
- Participate in scoping exercises and contribute to selecting appropriate testing methodologies.
- Support security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
- Assist in testing AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
- Contribute to the development of internal GenAI security testing checklists and methodologies aligned with OWASP Top 10 for LLMs.
Requirements
- Experience in information security, penetration testing, or a related field; coursework or experience in software development, DevOps, or scripting is highly desirable.
- At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
- Foundational understanding of web application architecture, networking, and operating system security.
- Familiarity with common penetration testing tools (Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
- Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
- Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
- Basic understanding of cloud environments (AWS, Azure, or GCP) and related security considerations.
- Exposure to SAST/DAST tools and secure code review practices is desirable.
- Awareness of GenAI security risks such as prompt injection, LLM abuse, and insecure AI integrations.
Technologies
- Burp Suite
- Nmap
- Metasploit
- Nuclei
- Python
- Bash
- PowerShell
- AWS
- Azure
- GCP
- OWASP Top 10
Benefits
- Annual incentive bonus
- Country-specific benefits
About the Role
This position supports the offensive security function within Elsevier's Security Engineering team. It entails performing hands-on security testing, peer reviews, and validation of vulnerabilities and security controls, with a focus on automating security assurance processes. The role is hands-on and suited for security professionals who thrive in a collaborative, fast-paced environment and seek opportunities to grow.
About the Team
The Security Assurance team oversees the third-party penetration testing program, security control validation, and ongoing offensive security testing activities. This group collaborates across departments to elevate the organization’s security posture and ensure robust security practices are integrated throughout development and operations.