The Senior Penetration Tester works to test and improve the security of our clients’ systems and data across a wide range of industries. In this role, you will be responsible for the execution of all types of penetration tests, social engineering tests, and vulnerability scans, as well as compiling and writing client reports. As the Senior Penetration Tester, you will provide exceptional testing and high-quality deliverables to clients to help continued growth of our fast-paced company.
A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.
EDUCATION * Master’s or Bachelor’s degree in cybersecurity, management information systems, computer science, or relevant discipline
EXPERIENCE * At least 5 years of experience with penetration tests and vulnerability assessments; including internal, external, wireless, mobile, and web application testing * Performed network and application pen tests * Programming experience in one or more of the following languages: Ruby, Python, Perl, C, C++, Java, and C# * Proficiency in working with both Windows and Linux operating systems * Demonstrated ability to perform penetration testing from the network layer to the web application layer, culminating in the completion of a quality report * Familiarity with major cloud CSPs such as AWS, Azure, AliCloud, Google Cloud, and Rackspace, including their associated internal components and controls * Solid understanding of SOAP/REST/JSON web APIs and methodologies for testing them * Working knowledge of standard security assessment tools (e.g., NMAP, metasploit, Scapy, Burp Suite, SSLStrip, Ettercap, Nessus, Nikto, AppScan) * Involvement with CTF (Capture The Flag) and exploitation tools (HackTheBox profile preferred) * Background in Security Operations, Incident Response, forensics, red-teaming, or DevOps preferred
CERTIFICATIONS One of the following certifications required: * OSCP/eCPPT or other related penetration testing certifications * eWPT or other applicable web app cert
Two of the following certifications required: * GWAPT, CEPT, LPT, GPEN, CPT, GXPN, PenTest+, GAWN, GMOB, CRTOP
SKILLS * Background and understanding on networking, firewalls, and subnets * Understanding of security best practices * Thrives in a fast-paced environment * Excellent communication skills * Ability to work individually as well as collaboratively * A high degree of motivation * A security focused mindset * Proficiency with scripting languages (Python, Bash, JavaScript, PowerShell) * Ability to create, modify, write documents from command line, and write Bash scripts to automate or facilitate tasks
