UL

Senior Penetration Tester

UL$110K — $140K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • University Degree in a relevant discipline plus 3-5 years of related experience, ideally with cloud security testing skills.
  • Strong proficiency in low-level programming (C, C++, Assembly) and scripting, with experience in FPGA or hardware debugging as a plus.
  • Familiarity with various test equipment and ability to work in multi-disciplinary environments.
  • Excellent written and verbal communication skills, capable of distilling complex technical concepts for a broad audience.
  • A self-motivated team player who thrives on independent work and innovation in technical development.

Responsibilities

  • Lead security assessments for embedded products, IoT devices, web/mobile applications, and cloud infrastructures.
  • Perform comprehensive security evaluations including vulnerability discovery, exploitation, code review, and binary analysis.
  • Apply cybersecurity compliance standards to create effective test plans for diverse products.
  • Collaborate with clients to understand security objectives and deliver actionable reports with findings and recommendations.
  • Provide technical support in test planning, methodology development, staff training, and complex issue resolution.
  • Stay updated on the latest technical developments in physical attacks and contribute to internal R&D initiatives.
  • Implement advanced attack techniques involving multiple methodologies and conduct thorough evaluations of smart cards and embedded systems.

Benefits

  • Comprehensive health benefits including medical, dental, and vision coverage.
  • Wellness programs focused on mental and financial health.
  • Retirement savings options (401K) with industry-standard matching.
  • Generous paid time off policy including vacation, holidays, personal days, and sick leave.
  • Eligibility for annual bonus compensation with a target payout of 10% of base salary.
Full Job Description
Job Description

This role is Hybrid, 3 days a week on-site at our Northbrook, IL Office.

As a Senior Penetration Tester, you will lead technical engagements responsible for evaluating and testing the security of embedded systems, cloud environments, web applications and mobile applications.

You will identify and responsibly exploit vulnerabilities, validate implemented security controls, and deliver actionable, high-value reports to clients. The role combines hands-on technical expertise with customer collaboration and contributions to internal R&D for advancing attack methodologies.

Responsibilities

  • Lead end-to-end security assessment engagements for embedded products, IoT Medical & Industrial devices, Web/Mobile applications, and Cloud infrastructures.
  • Perform comprehensive security evaluations, including vulnerability discovery, exploitation, code review, fuzzing, binary analysis, and validation of implemented security controls across all target environments.
  • Interpret and apply cybersecurity compliance standards like EN18031, CRA, UK PSTI, UL Standards to diverse product types, translating requirements into effective test plans.
  • Collaborate closely with clients to understand their security objectives, provide technical guidance, and deliver clear, professional reports with findings, risk ratings, and remediation recommendations.
  • Provide high-level technical support in areas like test planning, methodology development, procedure updates, staff training, and resolution of complex quality or testing issues.
  • Maintains/improves technical knowledge by attending educational workshops, reviewing professional publications, obtaining applicable certifications, and participating in professional societies and cross-departmental task forces.
  • Follow-up with the latest technical developments in the physical attacks area that need to be contributed to the internal R&D developments in hardware (analogue and digital electronics) and software (C, C++, Assembly, and others) to enhance the level of our attacks and to explore new forms of attacks.
  • Implement sophisticated attacks requiring multiple techniques such as vulnerability analysis, signal processing, FPGA, optical, and others.
  • Undertake security evaluation attacks on smart cards or embedded systems. The main activity will be the real product analysis with the aim to highlight its strengths and weaknesses.
  • Specialize in the realization of innovative physical attacks using laser or EM techniques, in-depth understanding on how the products work with the aim to stress them using complex hardware techniques.
  • Conduct web application penetration testing (covering OWASP Top 10, API security, authentication/authorization flaws, business logic vulnerabilities, and modern web frameworks).
  • Perform mobile application security assessments on iOS and Android platforms, including static analysis, dynamic analysis, reverse engineering, and platform-specific vulnerability testing.
  • Execute cloud security testing and configuration reviews across AWS, Azure, GCP, or multi-cloud environments, focusing on identity and access management (IAM), network security, container/Kubernetes security, serverless architectures, storage security, and cloud misconfigurations.


Qualifications

  • University Degree (Equivalent to Bachelor's Degree) in Electronic/Computer Science/Computer Engineering/Electrical Engineering or a related discipline plus 3-5 years of related experience. Good skills in Cloud security testing preferred.
  • Proficiency in low-level programming (C, C++, Assembly) and scripting. Experience with FPGA, signal processing, or hardware debugging tools is a strong plus.
  • Familiar with test equipment and working in a multi-skills environment mixing electronic, optical, security, mechanical, and IT.
  • Excellent written and verbal communication skills, with the ability to explain complex technical concepts to both technical and non-technical stakeholders.
  • A self-motivated team player who can work independently and likes to bring new ideas for technical development.

Total Rewards: We understand compensation is an important factor as you consider the next step in your career. The estimated salary range for this position is $110,000 to $140,000 USD and is based on multiple factors, including job-related knowledge/skills, experience, geographical location, as well as other factors. This position is eligible for annual bonus compensation with a target payout of 10% of the base salary. This position also provides health benefits such as medical, dental and vision; wellness benefits such as mental and financial health; and retirement savings (401K) commensurate with the standard rewards offered in each individual location or country. We also provide full-time employees with paid time off including vacation (15 days), holiday and personal days (totaling 12 days) and sick time off (72 hours).

#LI-SG2

#LI-Hybrid

About UL

UL is a global safety certification company headquartered in Northbrook, Illinois. It was founded in 1894 and has been providing safety testing, inspection, and certification services for over 125 years. UL operates in over 100 countries and has more than 14,000 employees worldwide. The company's mission is to promote safe living and working environments by advancing safety science. UL's services cover a wide range of industries, including consumer products, industrial equipment, building materials, and more.
Learn more about UL
Size
14,700 employees
Industry
Founded
1900

Similar Jobs

More Jobs at UL

More Information Technology Jobs

Find similar Senior Penetration Tester jobs: