
Locus Recruiting
Penetration Tester Dallas, Texas
Salary: 150,000 – 180,000 per Year
Locus Recruiting is currently hiring for a full time Remote Penetration Tester. Below is the job description for your review.
You will regularly:
Working independently and collaboratively with a team to both lead and support the following work activities, where skills apply:
Application Penetration Testing (Browser-based, API, Mobile, IoT)
Threat Modeling
Source Code Reviews
Advises clients on technical security or compliance activities
Manages priorities and tasks to achieve utilization targets.
Operates with professionalism both internally and with clients.
Ensures quality reports and services are delivered efficiently and on time.
Continues to develop professional skills with relevant industry specific certifications or training. Maintains strong depth of knowledge in the practice area.
Collaborates with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
Escalates client and project-related issues to management in a timely manner to inform and engage the necessary resources to address the issue.
Contributes to thought leadership initiatives through blogs, conference speaking, and/or R&D functions.
Ability to travel up to 10% (potentially & during normal circumstances)
Application penetration testing and assessment tradecraft and methodologies (including browser-based, API, thick client, and Mobile)
Strong working knowledge of at least two programming or scripting languages
Excellent verbal and written communication skills, including technical writing of assessment reports, presentations, and operating procedures.
Client-centric consulting with high level of collaboration.
Shows an aptitude for leadership both through practice maturation and by mentoring junior teammates.
Strong understanding of security principles, policies, and industry best practices.
Strong understanding of various compliance frameworks (PCI DSS, FedRAMP, HIPAA, etc.).
Minimum of 5 years experience in a consulting/professional services role
Minimum of 5 years experience in Application Security and/or Software Development
Experience testing against one or more IT security compliance frameworks, such as PCI, FISMA, HIPAA, FEDRAMP, or HITRUST
Familiarity with Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Software Assurance Maturity Model (SAMM), National Institute of Standards and Technology (NIST) Special Publications, and PTES (Penetration Testing Execution Standard).
Software development/engineering
Cloud Service penetration testing tradecraft and methodologies across multiple service providers (e.g. AWS, GCP, etc.).
Mobile platform penetration testing tradecraft and methodologies across both widely-used platforms (iOS and Android).
Network/host-based penetration testing tradecraft and methodologies.
Cloud Service penetration testing specifically against AWS and GCP services
Mobile device and application penetration testing on both iOS and Android platforms
Red/Purple team operations
Benefits:
Health, dental, and vision insurance with an employer contribution
Flexible paid time off (employees are encouraged to spend four weeks away from the office each year)
A generous 401(k) plan
Stock Appreciation Rights (SARs)
A corporate wellness programs
Tuition reimbursement
Salary Range: $100,000 to $180,000 (will be based off experience)
Thank you,