Penetration Tester / Security Assessor

ASM Research$110K — $130K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science or related field or equivalent experience
  • 5-10 years in systems security, with 2+ years in info security, penetration testing, or ethical hacking
  • Experience planning and conducting penetration tests against networks and web applications
  • Proficiency with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz
  • Familiarity with network scanning, enumeration, and exploiting vulnerabilities
  • Understanding of web technologies including HTML, JavaScript, and SQL

Responsibilities

  • Create cyber-intelligence tools and methods for security risk mitigation
  • Perform infrastructure penetration testing to find vulnerabilities
  • Conduct web application penetration testing focusing on OWASP Top 10
  • Emulate known threat actors' tactics using threat intelligence
  • Collaborate with cybersecurity teams to enhance automation and detection
  • Engage with technical and non-technical audiences to explain techniques and results

Benefits

  • Comprehensive benefits package including health, dental, and vision insurance
  • Retirement savings plans with employer contributions
  • Ongoing training and professional development opportunities
  • Flexible work environment and work-from-home options
  • Paid time off and holidays
Full Job Description
Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture.
  • Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization's security posture.
  • Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities.
  • Leverage threat intelligence to emulate known threat actors' tactics, techniques, and procedures.
  • Partner with various cybersecurity teams to improve automation and detection of threat actors.
  • Engage with technical and non-technical audiences to articulate both techniques and results.

Minimum Qualifications
  • Bachelor's Degree in Computer Science or a related field or equivalent experience.
  • 5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking.

Other Job Specific Skills
  • Must possess demonstrated experience planning and conducting penetration tests against networks and web applications.
  • Demonstrated experience conducting vulnerability assessments and penetration tests.
  • Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz.
  • Hands-on experience with penetration testing tools and frameworks.
  • Portfolio of security assessments or CTF achievements (preferred).
  • Experience with network scanning, enumeration, and exploiting vulnerabilities.
  • Proficiency in Windows, Linux, and macOS environments.
  • Understanding of system hardening techniques and common misconfigurations.
  • Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits.
  • Familiarity with bash, PowerShell, or other scripting languages for automation.
  • Understanding of web technologies, including HTML, JavaScript, and SQL.

Preferred Skills
  • Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems.
  • Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk.
  • Ability to analyze and critique code for security vulnerabilities.
  • Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows.
  • Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, HTTP, VPNs, firewalls, routers, switches).


Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

Similar Jobs

More Jobs at ASM Research

More Information Technology Jobs

Find similar Penetration Tester / Security Assessor jobs: