Security Assurance Penetration Tester
Job Description
A hands-on Security Assurance Penetration Tester will join RELX/Elsevier's Security Engineering team in Pennsylvania on site. The role centers on performing security testing, validating vulnerabilities, and automating security assurance processes, with collaboration across product and development teams and a focus on GenAI security. Salary is USD 71,600 to 119,400 per year.
Responsibilities
- Track and triage findings from third-party assessments, ensuring timely follow-up and remediation tracking.
- Collaborate with development, platform, and product teams to communicate findings, oversee remediation efforts, and improve overall security posture.
- Facilitate post‑assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
- Maintain program documentation, test records, and reporting artifacts.
- Conduct penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
- Perform peer review of penetration testing deliverables, including test plans, findings, and final reports.
- Participate in scoping exercises and contribute to the selection of appropriate testing methodologies.
- Support security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
- Assist in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
- Contribute to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
- Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
- At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
- Foundational understanding of web application architecture, networking, and operating system security.
- Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
- Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
- Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
- Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
- Exposure to SAST/DAST tools and secure code review practices is desirable.
- Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations).
Technologies
- Burp Suite
- Nmap
- Metasploit
- Nuclei
- Python
- Bash
- PowerShell
- AWS
- Azure
- GCP
- OWASP Top 10
Benefits
- Annual incentive bonus
- Country-specific benefits
About the Role
This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. It is a hands-on opportunity for a motivated security professional eager to grow in a collaborative, fast-paced environment.
About the Team
The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.