TTM Technologies Inc

IT Security - Vulnerability Assessment

TTM Technologies Inc$100K — $120K *
US-AnywhereRemote in Texas, US
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of hands-on experience in penetration testing, red teaming, or offensive security.
  • Strong knowledge of web application security (OWASP Top 10) and network penetration testing.
  • Proficiency with offensive security tools like Burp Suite, Metasploit, and Nmap.
  • Scripting/programming experience in Python, Go, PowerShell, or similar.
  • Experience validating vulnerabilities from scanners like Nessus or Qualys.
  • Solid understanding of cloud security concepts and services from AWS, Azure, or GCP.
  • Strong written and verbal communication skills for translating technical findings into business risk.

Responsibilities

  • Plan and execute penetration tests against web applications, APIs, and cloud environments.
  • Conduct red team engagements simulating real-world adversary tactics aligned with MITRE ATT&CK.
  • Deliver actionable reports with clear remediation guidance.
  • Build and maintain offensive security tooling and automation infrastructures.
  • Develop custom exploits and scripts for large-scale testing.
  • Integrate offensive testing into CI/CD pipelines for continuous attack simulation.
  • Contribute to purple team exercises to enhance detection and response capabilities.

Benefits

  • Health and well-being programs including medical, dental, and vision insurance.
  • 401K and Flexible Spending Account options.
  • Health Savings Account and accident benefits.
  • Life insurance and disability benefits.
  • Paid vacation and holidays.
Full Job Description
Job Title: IT Security Vulnerability Assessment

Summary

We are seeking a hands-on Offensive Security Engineer to join our security team. In this hybrid role, you will operate as a penetration tester, offensive security engineer, and vulnerability validator - proactively identifying, exploiting, and validating weaknesses across our applications, infrastructure, cloud environments, and people. You will partner closely with engineering, DevOps, and detection/response teams to ensure findings are real, prioritized correctly, and remediated effectively. This is an ideal role for someone who loves breaking things, building tooling to break things at scale, and helping defenders close the gap.

Duties and Responsibilities:
  • Plan and execute penetration tests against web applications, APIs, cloud environments (AWS/Azure/GCP), networks, and internal systems.
  • Conduct red team-style engagements simulating real-world adversary tactics, techniques, and procedures (TTPs) aligned with frameworks like MITRE ATT&CK.
  • Deliver clear, actionable reports with reproducible steps, business impact, and remediation guidance.
  • Offensive Engineering
  • Build, maintain, and improve internal offensive security tooling, automation, and attack infrastructure.
  • Develop custom exploits, proof-of-concept code, and scripts to test controls at scale.
  • Integrate offensive testing into CI/CD pipelines (continuous attack simulation, automated recon, etc.).
  • Contribute to purple team exercises to validate and improve detection and response capabilities.
  • Vulnerability Validation & Triage
  • Validate vulnerabilities reported by scanners, bug bounty programs, third-party assessments, and internal researchers to eliminate false positives and confirm exploitability.
  • Reproduce reported issues, assess real-world impact, and assign accurate severity (CVSS, business risk).
  • Partner with engineering teams to verify fixes and re-test remediations.
  • Help prioritize the vulnerability backlog based on exploitability and business context.
  • Collaboration & Enablement
  • Work with product and engineering teams to provide secure design guidance and threat modeling support.
  • Mentor engineers on secure coding and common attack patterns.
  • Contribute to security training, internal write-ups, and lessons learned.


Qualifications
  • 2+ years of hands-on experience in penetration testing, red teaming, or offensive security (adjust based on seniority).
  • Strong knowledge of web application security (OWASP Top 10), network penetration testing, and common exploitation techniques.
  • Proficiency with offensive tooling such as Burp Suite, Metasploit, Nmap, BloodHound, Cobalt Strike (or equivalents), Impacket, etc.
  • Scripting/programming experience in at least one of: Python, Go, PowerShell, Bash, or similar.
  • Experience validating vulnerabilities from scanners (e.g., Nessus, Qualys, Snyk, Wiz, Burp) and distinguishing true positives from noise.
  • Solid understanding of cloud security concepts and at least one major cloud provider (AWS, Azure, or GCP).
  • Strong written and verbal communication skills - able to translate technical findings into business risk.


Preferred
  • Industry certifications such as OSCP, OSEP, OSWE, CRTO, GPEN, GXPN, or equivalent.
  • Experience with container/Kubernetes security, CI/CD pipeline attacks, or IaC review.
  • Exploit development, reverse engineering, or malware analysis experience.
  • Bug bounty participation, CVE credits, open-source security contributions, or conference talks.
  • Familiarity with detection engineering, SIEM, or EDR platforms (for purple teaming).


Compensation and Benefits:

TTM offers a variety of health and well-being benefit programs. Benefit options include medical, dental, vision, 401K, Flexible Spending Account, Health Savings Account, accident benefits, life insurance, disability benefits, paid vacation & holidays. Benefits are available 1st of the month following date of hire.

Compensation for roles at TTM Technologies varies depending on a wide array of factors including but not limited to the specific office location, role, skill set and level of experience. As required by local law, TTM provides a reasonable range of compensation for roles that may be hired in New York, California and Colorado. For California-based roles, compensation ranges are based upon specific physical locations.

Export Statement:
Must comply with TTM Export Control Policies and Procedures and all applicable laws including ITAR, EAR and OFAC including but not limited to: a) being able to identify ITAR product on the manufacturing floor and understand that access to these products and related technical data is restricted to only US Citizens and US Permanent Residents; b) recognition of Foreign Person visitors by badge differentiation; c) understand and follow authorization procedures for bringing foreign visitors into facilities (VAL); d) understand the Export and ITAR requirements for shipments leaving the US; e) manage vendor approvals for ITAR manufacturing and services.

About TTM Technologies Inc

TTM Technologies, Inc. is a leading global printed circuit board (PCB) manufacturer, focusing on quick-turn and volume production of technologically advanced PCBs, backplane assemblies and electro-mechanical solutions. The company has a diversified customer base, including manufacturers of aerospace and defense, networking and communications, computing and storage, and medical and industrial equipment. TTM Technologies has manufacturing facilities in North America, Europe and Asia, and has been recognized for its commitment to sustainability and corporate social responsibility. The company was founded in 1978 and is headquartered in Costa Mesa, California.
Learn more about TTM Technologies Inc
Size
16,100 employees
Market Cap
$1.5 billion
Industry
Net Income
$189.1 million
5 Year Trend
-2.4%
Revenue
$2.1 billion
NASDAQ

Similar Jobs

More Jobs at TTM Technologies Inc

More Information Technology Jobs

Find similar IT Security - Vulnerability Assessment jobs: