Associate, Compliance Security Penetration Tester
Summary
Perform penetration testing and security assessments (network, web app, API, cloud, mobile, wireless) for global clients at cybersecurity consultancy Coalfire, advising on technical security and IT compliance frameworks.
About Coalfire
What You'll Do
- Advises clients on technical security or compliance activities
- Manages priorities and tasks to achieve delivery utilization targets.
- Operates with professionalism both internally and with clients.
- Ensures quality products and services are delivered on time.
- Continues to develop professional skills with relevant industry specific certifications. Maintains strong depth of knowledge in the practice area.
- Collaborates with project managers, quality management, sales, and other delivery team members to drive customer satisfaction and meet project deliverables.
- Develop processes, procedures, and methodologies to enhance testing processes and experience
- Assist with report generation and quality assurance processes
- Develop client relationships
- Assist in the scoping of prospective engagements, leading engagements from initial stages through implementation and remediation
- Manage project escalations of current testing being conducted
- Mentor and develop less experienced staff
- Contribute to the Penetration Testing Team overall success by managing your team to meet various business objectives and metrics
What You'll Bring
- Bachelor's degree (four-year college or university) or equivalent combination of education and work experience
- 3+ years’ experience in information security with Web Application and Network penetration testing experience
- Experience working with enterprise environments
- Hands-on experience with scripting languages such as Python, Powershell, Shell, or Ruby
- Experience with one or more IT security compliance frameworks, such as PCI, FISMA, HIPAA, FEDRAMP, or HITRUST
- One to three (1-3) years of experience in an IT Security Audit and/or Compliance role
- Experience interacting with management in a consultative manner
- Strong IT understanding with respect to networks, servers, workstations, and applications
- Excellent communication and presentation skills
- Ability to travel up to 20%
Bonus Points
- Deep experience engaging clientele in consulting-related environments
- Experience leading penetration team engagements
- Reverse engineering malware, data obfuscators, or ciphers
- An aptitude for technical writing, including assessment reports, presentations, and operating procedures
- Strong understanding of security principles, policies, and industry best practices
- Experience working with C and various compiler toolchains
- Community contributions or participation including
- CTF, Hack-the-box, or cyber-defense competitions
- Speaking or presentations
- Public security research