Senior Associate, Offensive Security (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Associate, Offensive Security (Cybersecurity): Conducting penetration tests, adversary simulations, and red and purple team exercises across on-premises, cloud, and hybrid environments with an accent on threat-informed testing, vulnerability validation, and actionable remediation guidance. Focus on mapping attack techniques to realistic attack paths, improving detection capabilities, and building repeatable tooling and playbooks in a highly regulated pharmaceutical environment.
Location: New York City, United States; hybrid work with 2–3 days per week in the assigned office. This role is not remote. Travel is less than 5% as required. Candidates must have permanent U.S. work authorization; visa sponsorship is not available.
Salary: $79,400–$132,400 annual base salary, plus eligibility for a 7.5% bonus target.
Company
is a global pharmaceutical company developing medicines and healthcare solutions.
What you will do
- Conduct penetration tests and adversary simulation exercises across on-premises, cloud, and hybrid environments.
- Support red team and purple team engagements by executing test plans, collecting evidence, and assessing defensive controls.
- Identify, validate, and document security weaknesses with proof-of-concept evidence and remediation recommendations.
- Translate offensive security findings into improvement actions for detection, engineering, remediation, and risk teams.
- Map observed techniques to attacker behaviors and realistic attack paths.
- Improve offensive security tooling, automation, repeatable testing methods, reporting standards, and playbooks.
Requirements
- Bachelor’s degree in information security, computer science, engineering, or a related field with at least 2 years of relevant cybersecurity experience; equivalent combinations of education and experience are accepted.
- Hands-on experience with penetration testing or security assessments, including reconnaissance, exploitation validation, and reporting.
- Strong understanding of attack techniques and enterprise security across identity, endpoints, networks, and cloud services.
- Ability to document technical findings and communicate risk and remediation guidance to technical stakeholders.
- Working knowledge of Python, PowerShell, Bash, or another scripting or programming language used for security work.
- Permanent U.S. work authorization is required; U.S. visa sponsorship is unavailable.
Nice to have
- Experience with MITRE ATT&CK-aligned red team and adversary emulation methodologies.
- Application, cloud, network, identity, social engineering, or phishing testing experience.
- Experience in pharmaceutical, biotech, life sciences, healthcare, or another regulated industry.
- Certifications such as CISSP, OSCP, CRTO, GPEN, or GXPN.
- Experience improving SOC detections and building standardized security playbooks.
Culture & Benefits
- Work in a highly regulated pharmaceutical environment with cross-functional security, infrastructure, cloud, and risk teams.
- Hybrid office schedule with 2–3 days per week onsite and limited business travel.
- Comprehensive medical, prescription drug, dental, vision, and retirement benefits.
- matching contributions and an additional retirement savings contribution.
- Paid vacation, holidays, personal days, caregiver/parental leave, and medical leave.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →