SeniorLead Security Engineer AI
Job Summary
We are seeking an experienced Penetration Tester to establish and operate a robust repeatable security-testing capability for our products and supporting infrastructure. The role will design the penetration-testing framework toolset processes and test environments needed to conduct regular assessments across web applications APIs virtual machines cloud configurations and related infrastructure. A key objective is to validate defenses against modern attack techniques and maintain high security coverage across the business product offering.
- Design implement and maintain a penetration-testing framework covering methodology scope definition test frequency evidence collection reporting retesting and risk tracking
- Build configure and maintain the tools scripts environments and automation required for recurring security assessments
- Perform manual and automated penetration testing of web applications customer-facing portals APIs virtual machines operating systems networks and cloud environments (IAM storage networking logging secrets containers)
- Identify vulnerabilities validate exploitability assess business impact and provide practical prioritized remediation recommendations
- Design attack scenarios reflecting modern attacker behavior including automated reconnaissance vulnerability discovery credential attacks and attack chaining
- Collaborate with software engineering DevOps cloud infrastructure product and security teams to explain findings support remediation and confirm fixes through retesting
- Integrate appropriate security testing and scanning into CI/CD pipelines and engineering workflows
- Stay current on vulnerabilities offensive-security techniques cloud-security threats OWASP guidance and emerging attack trends
- 8 years of hands-on experience in penetration testing application security offensive security red teaming or a similar role
- Proven experience testing web applications APIs cloud infrastructure virtual machines operating systems and network services
- Strong knowledge of OWASP Top 10 OWASP API Security Top 10 common web and API attack techniques and secure-development practices
- Practical experience assessing one or more major cloud platforms: AWS Microsoft Azure or Google Cloud Platform
- Strong understanding of identity and access management authentication authorization session security networking encryption secrets management and common cloud misconfigurations
- Hands-on experience with tools such as Burp Suite Nmap Wireshark Metasploit Nessus/OpenVAS sqlmap and cloud-security tools
- Proficiency in scripting or programming using Python Bash PowerShell JavaScript or similar languages
- Ability to independently plan and execute tests document evidence communicate risk and deliver concise actionable technical reports
- Strong communication skills and the ability to work constructively with engineering and business stakeholders
- Experience building internal penetration-testing frameworks labs tools scripts or security-test automation
- Experience integrating security controls or testing activities into CI/CD pipelines
- Knowledge of Docker Kubernetes Terraform infrastructure as code and container-security testing
- Relevant certifications such as OSCP OSWE OSEP CRTO CREST GPEN GWAPT PNPT CISSP or cloud-security certifications
Required Experience:
Staff IC