TL;DR
Penetration Tester (Cybersecurity): Performing manual penetration testing against web, thick-client, and mobile applications and critical infrastructure with an accent on vulnerability identification and remediation. Focus on process improvement, automation, and technical quality assurance to support the Application Security Framework.
Location: Nashville, Raleigh (USA)
Company
hirify.global is a leading global wealth manager and the leading universal bank in Switzerland, providing diversified asset management solutions and focused investment banking capabilities.
What you will do
- Perform manual penetration testing against web, thick-client, and mobile applications, as well as critical infrastructure (e.g., Active Directory, LDAP).
- Identify and report vulnerabilities using common methodologies, with extensive knowledge of OWASP.
- Communicate with application teams on remediating vulnerabilities.
- Utilize technologies and tools such as Burp Suite, DAST, and Azure cloud.
- Participate in process improvements and automation.
- Perform technical QAs, including false-positive analysis and risk rating reviews.
Requirements
- Ideally, 5+ years of hands-on experience in penetration testing web, thick-client, and mobile applications.
- Hands-on experience with testing critical infrastructure such as AD, LDAP, DNS, etc.
- Proficient with Microsoft o365 suite – specifically focused on PowerPoint, Excel, Outlook, etc.
- Demonstrates exceptional attention to detail and possesses strong problem-solving skills.
- Track record of explaining technical issues to application teams and assisting them in resolving issues.
- Ability to properly document vulnerabilities and produce penetration test reports.
Nice to have
- Certifications in cyber security area, such as OSWE, OSCP, CompTIA Security+, Burp Suite Certified Practitioner.
Culture & Benefits
- Committed to fostering and advancing diversity, equity, and inclusion.
- Collaboration is at the heart of everything we do.
- New challenges, a supportive team, and opportunities to grow.
- Flexible working options when possible.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →