Aon

Principal Application Security Penetration Tester

Aon • $93K — $155K *
US-AnywhereRemote in Canada
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of hands-on penetration testing and/or bug bounty experience
  • Expertise in development and/or source code review in languages like Java, C#, PHP, Python, etc.
  • Familiarity with testing tools such as Burp Suite and code review tools like Fortify
  • Deep knowledge of common software vulnerabilities (OWASP Top 10, CWE/SANS Top 25)
  • Solid understanding of Unix, Windows, and network security
  • Excellent communication skills in English for technical and business audiences

Responsibilities

  • Conduct complex hybrid web application security assessments
  • Write test harnesses to identify and proof-of-concept security vulnerabilities
  • Communicate vulnerabilities to client development teams during and post-assessment
  • Document technical issues and provide tailored remediation recommendations
  • Assist in pre-sales scoping activities for penetration testing engagements
  • Mentor junior engineers and provide career development guidance
  • Engage in vulnerability research for blogs, talks, and whitepapers
  • Contribute to internal business operations and process improvements
  • Develop and improve internal tooling for reporting and penetration testing
  • Participate in recruitment of new penetration testing talent

Benefits

  • Comprehensive benefits package
  • Flexible working arrangements, including remote work options
  • Two 'Global Wellbeing Days' each year for personal focus
  • Support for continuous learning and professional development
  • Inclusive environment promoting diversity and work/life balance
Full Job Description
The Proactive Security Testing team is looking for smart, energetic, and motivated individuals to add to its team. We provide a challenging and exciting work environment that offers a healthy combination of autonomy and senior level support. Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and are engaged in a variety of continuous security research projects.

The location of this position flexible within BC and ON to work near an office or remotely.

Applicants must be legally authorized to work in Canada. This role is not eligible for sponsorship, and we are unable to sponsor or take over sponsorship of an employment visa or work permit.

The salary range for this position is $93k - $155K CAD. The actual salary will vary based on applicant's education, experience, skills, and abilities, as well as internal equity. Aon also offers you a generous incentive earning opportunity and a comprehensive benefits package.

What the day will look like

As a Principal Application Security Tester (termed internally as a "Security Testing Manager"), you will serve as a senior member of the penetration testing team. In addition, the person in the role will do the following:
  • Conduct complex hybrid web application security assessments, involving code review and dynamic application testing applying a combination of static and dynamic source code analysis techniques.
  • Write test harnesses to help identify and proof-of-concept potential security vulnerabilities.
  • Clearly communicate vulnerabilities to client development teams during and post-assessment.
  • Document technical issues identified during security assessments, outlining the associated risks for clients, and providing tailored recommendations for remediation.
  • Assist colleagues in pre-sales scoping activities for penetration testing engagements.
  • Offer technical mentorship and career development guidance to junior engineers within the organization.
  • Engage in vulnerability research to produce blog posts, conference talks, whitepapers, etc.
  • Contribute to internal business operations by participating in and suggesting process improvements.
  • Develop, update, and improve internal tooling used for reporting and penetration testing.
  • Partner with the team in the recruitment of new penetration testing talent including reviewing resumes and conducting interviews.

Skills and experience that will lead to success.
  • 4+ years of hands-on penetration testing and/or bug bounty experience.
  • Some expertise in development and/or source code review, focusing on languages such as Java, C#, C/C++, PHP, Ruby, Python, Go, Swift, Objective C/C++, Kotlin, etc.
  • Up to date experience with testing techniques and tooling, such as Burp Suite and other fuzzers/proxies.
  • Up to date experience with code review scanning tools, such as Fortify, Semgrep, etc.
  • Deep knowledge of common software vulnerabilities, such as those described in the OWASP Top 10 and CWE/SANS Top 25.
  • Possesses a solid grasp of Unix, Windows, and network security.
  • Ability to work remotely as part of a distributed team and travel to client sites when required.
  • Excellent communication skills (written & verbal) in English, to present complex technical topics concisely to both technical and business audiences.

These skills/experiences are a plus:
  • Experience at an existing consulting firm as a penetration tester
  • Experience performing hands-on mobile application penetration testing on iOS and/or Android platforms.
  • Experience with Bug Bounties, reporting critical/high risk issues to programs.
  • Degree in Computer Science, Information Systems, Engineering or related major and/or equivalent experience.
  • Reputable security certifications, including but not limited to: OSCP, OSWE, GWAPT, OSEE OSCE/OSED, GPEN, GXPN, BSCP
  • Produced public facing research and/or delivered presentations at well-known industry security conferences.

How we support our colleagues

In addition to our comprehensive benefits package, we encourage a diverse workforce. Plus, our agile, inclusive environment allows you to manage your wellbeing and work/life balance, ensuring you can be your best self at Aon. Furthermore, all colleagues enjoy two "Global Wellbeing Days" each year, encouraging you to take time to focus on yourself. We offer a variety of working style solutions, but we also recognise that flexibility goes beyond just the place of work... and we are all for it. We call this Smart Working!

Our continuous learning culture inspires and equips you to learn, share and grow, helping you achieve your fullest potential. As a result, at Aon, you are more connected, more relevant, and more valued.

Aon values an innovative, diverse workplace where all colleagues feel empowered to be their authentic selves.

#LI-KH1

About Aon

Aon plc is a leading global professional services firm that provides a broad range of risk, retirement and health solutions. The company was founded in 1982 and is headquartered in London, England. Aon operates in more than 120 countries and has a team of over 50,000 employees. The company's services include risk management, insurance brokerage, reinsurance brokerage, human capital consulting, and retirement solutions. Aon is committed to helping clients manage risk and achieve their goals, and is known for its innovative solutions and industry expertise. The company is listed on the New York Stock Exchange under the ticker symbol AON.
Learn more about Aon
Size
50,000 employees
Market Cap
$62.1 billion
Industry
Net Income
$1.9 billion
5 Year Trend
+5.3%
Revenue
$11 billion
NASDAQ

Similar Jobs

More Jobs at Aon

More Information Technology Jobs

Find similar Principal Application Security Penetration Tester jobs: