Pentester and Vulnerability Mgt Engineer

2 weeks ago


Charlotte, United States Belk Full time

Security Engineer – Penetration Testing & Vulnerability Management

We are looking for a penetration tester/vulnerability engineer to join our team to help protect the organization from cyber threats. As a penetration tester, you will be responsible for conducting ethical hacking activities to identify and exploit vulnerabilities in systems, networks, applications, and devices. You will be involved in red teaming, purple teaming, and active threat-hunting exercises to simulate real-world attacks and test the effectiveness of our security controls and incident response capabilities. You will also be expected to lead and manage vulnerability and patch management programs to ensure timely remediation of security issues.

This role is fully remote with quarterly travel to Belk, Inc. headquarters and must be worked in the ET time zone. This role will report to the Manager, Cybersecurity Operations & Incident Response.

Essential Duties and Responsibilities

Vulnerability Management

Compiling and tracking vulnerabilities and mitigation results to quantify program effectiveness.Creating and maintaining vulnerability management policies, procedures, and trainingAnalyzing cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents related to cyber defense assessment.Prepare reports identifying technical and procedural findings and providing recommended remediation strategies/solutions.Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., container registry scanning, open-source vulnerability scanning, network/host vulnerability scanning, cloud security posture management, and source code scanning.Analyze CIS benchmarks compliance for multiple platforms, including on-premises and cloud resources, and generate reports to achieve compliance by meeting organizational security standards.Maintain weekly reports for work-in-progress efforts across cybersecurity operations resources.Manage the exception process for vulnerabilities, patching, or pen-testing findings that cannot meet Belk’s Standards and/or the remediation SLA.

Penetration Testing

Perform formal penetration tests on web-based applications, networks, and computer systems to include Windows environments from initiation to closure.Threat modelingCarry out testing of the cloud environment to expose weaknesses in security.Determine methods that attackers could use to exploit weaknesses and logic flaws.Perform security reviews of application designs, source code, and deployments as required, covering all types of applications (web applications, web services, mobile applications, SaaS)Perform physical security reviews.Participate in Security Assessments and IT auditing of networks, systems, and applications.Use, design, and create penetration tools and tests.Document findings for management and technical staff and recommend mitigating actions.

Required Knowledge and Skills

Proficiency in using penetration testing tools like Metasploit, Burp Suite, Nmap, Wireshark, and vulnerability scanners.Understanding of standard network protocols, operating systems (Windows, Linux, macOS), and web technologies.Knowledge of common web application vulnerabilities like SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF).Familiarity with scripting languages like Python, Bash, or PowerShell to automate tasks and develop custom tools.Solid understanding of cybersecurity principles, secure coding practices, cloud infrastructure, and network security controls.Knowledge of common security frameworks and compliance standards, such as OWASP, PCI DSS, NIST, and MITRE ATT&CK® Framework.Strong analytical thinking and problem-solving abilities to identify vulnerabilities, analyze their impact, and recommend appropriate solutions.Knowledge of system administration concepts, including server configuration, user, and patch management.Excellent communication skills to communicate findings, vulnerabilities, and recommendations effectively to technical and non-technical stakeholders.Willingness to continuously learn new tools, methodologies, and technologies in the rapidly evolving field of cybersecurity.Understanding the retail business context to prioritize risks and align security assessments with organizational objectives is essential.Ability to work effectively as a team, collaborate with other security professionals, and share knowledge and expertise.

General Requirements:

A bachelor’s degree in computer science, Information Security, or a related field is desirable.At least one of the following certifications: OSCP, GPEN, PNPT, PenTest+, or similar certification3+ years of overall IT experience.3+ years of experience in vulnerability management.3+ years of experience in ethical hacking.2+ years of experience in incident management.3+ years of experience in systems management and administration is desireable

#LI-REMOTE

#LI-CR1

#IND3



  • Charlotte, United States Belk, Inc. & Belk eCommerce LLC Full time

    Security Engineer - Penetration Testing & Vulnerability Management We are looking for a penetration tester/vulnerability engineer to join our team to help protect the organization from cyber threats. As a penetration tester, you will be responsible for conducting ethical hacking activities to identify and exploit vulnerabilities in systems, networks,...


  • Charlotte, United States Randstad Digital Full time

    ResponsibilitiesProvide vulnerability management and secure configuration baseline management oversight and governance for Infosys VM/SCM programs. Adjudicate risk-acceptance ("exception") requests and false positive requests, review VM metrics, shape and govern based on trends being presented to us by InfosysQualificationsLooking for strong AWS experience...


  • Charlotte, North Carolina, United States Bank of America Full time

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.This job is responsible for assessing the bank's technologies, applications, and...


  • Charlotte, United States Bank of America Full time

    Description : Senior Adaptive Threat Replication Engineer (AKA Red Team, Penetration Testing, Advanced Vulnerability Assessments Engineer) Are you passionate about cyber security and looking to work with some of the best information security professionals in the world and in challenging environments? Bank of America is hiring top talent to join our...


  • Charlotte, United States Jones Grove IT Recruiting Full time

    Cyber Security Engineer Permanent Position Charlotte, NC – Hybrid The Cyber Security Engineer is responsible for assisting with the day-to-day operations of securing the various information systems. This role will be tasked with designing, implementing, and maintaining security solutions. This role will take part in a new Cyber Security road map and offers...

  • IT Procurement Lead

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID C) DescriptionAs our company continues to expand its digital presence and leverage technology for business growth, we are seeking an experienced and knowledgeable IT Security and Compliance Manager to join our team. This critical role will be responsible for establishing and maintaining robust security measures, ensuring compliance with relevant...

  • IT Procurement Lead

    1 month ago


    Charlotte, United States Babcock and Wilcox Company Full time

    Job ID - (2400001C) Description As our company continues to expand its digital presence and leverage technology for business growth, we are seeking an experienced and knowledgeable IT Security and Compliance Manager to join our team. This critical role will be responsible for establishing and maintaining robust security measures, ensuring compliance...


  • Charlotte, United States Donato Technologies Inc Full time

    Greetings from Donato Technologies Inc. We have an immediate opening with my client. If you are looking for a new project, please send me a copy of your updated resume Role title: Static Code/SCA Principal Engineer Start Date: 05/15/2024 End Date: 01/15/2025 Location: Atlanta, Georgia & Charlotte, North Carolina Required Skills (Be specific): (hands on and...

  • Security Engineer

    4 days ago


    Charlotte, United States TEKRRA1 Full time

    Requirements: Engage in security consultation for internal projects to ensure alignment with corporate security policies and standards. Monitor and address vulnerabilities and security incidents. Analyze security logs for potential threats. Contribute to the design, testing, and maintenance of security solutions across various domains including...

  • Database Engineer 2

    2 weeks ago


    Charlotte, United States Mindlance Full time

    Job Descriptions: In this contingent resource assignment, you may: Participate in low to moderately complex initiatives and identify opportunity for process improvements within Database Engineering. Review and analyze basic or tactical Database Engineering assignments or challenges that require research, evaluation, and selection of alternatives, related to...


  • Charlotte, United States Teknosys Full time

    Job Title: Cyber Security EngineerLocation: Raleigh, NC (Hybrid) Job Description:We are currently seeking a proficient Cyber Security Engineer to join our esteemed team. The successful candidate will play a pivotal role in fortifying our security infrastructure, specializing in identifying single sign-on solutions and enhancing database security protocols....

  • Project Engineer

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID DescriptionA Project Engineer is directly responsible for the technical excellence and the technical coordination of assigned projects and indirectly responsible for project profitability, with these responsibilities crossing multiple engineering disciplines. This individual will guide the engineering process in addition to monitoring all phases of...

  • Security Engineer

    2 weeks ago


    Charlotte, United States TEKRRA1 Full time

    Job DescriptionJob DescriptionRequirements: Engage in security consultation for internal projects to ensure alignment with corporate security policies and standards. Monitor and address vulnerabilities and security incidents. Analyze security logs for potential threats. Contribute to the design, testing, and maintenance of security solutions across various...

  • Project Engineer

    3 weeks ago


    Charlotte, United States Babcock and Wilcox Company Full time

    Job ID - (24000028) Description A Project Engineer is directly responsible for the technical excellence and the technical coordination of assigned projects and indirectly responsible for project profitability, with these responsibilities crossing multiple engineering disciplines. This individual will guide the engineering process in addition to...


  • Charlotte, United States Nenni and Associates Full time

    Overview: Our client is a very well-established consulting engineering firm that is currently seeking a Senior Mechanical Engineer to join their team within the Charlotte market! Job Duties and Responsibilities: Collaborate and mentor junior engineers to design the mechanical and plumbing components of energy-efficient buildings. Knowledge of building...


  • Charlotte, United States TEKRRA1 Full time

    Job DescriptionJob DescriptionDatabase Operations (DB OPS) Spearhead computer security incident response initiatives for intricate eventsConduct in-depth technical investigations of security incidents and conduct post-incident digital forensics to pinpoint causes and propose future mitigation strategies Offer security consultancy on major projects for...

  • Civil / Site Engineer

    2 weeks ago


    Charlotte, United States Hazen and Sawyer Full time

    Job DescriptionJob DescriptionWe are seeking a Site/Civil Engineer with a minimum 2 years of experience in the design and regulatory permitting of site plans, drainage studies, stormwater collection systems, Best Management and Low-impact Development practices, and erosion control facilities for construction. The ideal candidate should have successfully...


  • Charlotte, United States Engineering Design and Testing Full time

    Job DescriptionJob DescriptionCandidates should have previous forensic experience. Qualified candidates MUST currently hold a valid US PE license - No Exceptions! Unqualified candidates will not receive a response.Do you like to tear things apart to figure out what made them fail/break? Washing machines, toasters, ovens, etc. You never know what you will...


  • Charlotte, United States AT-NET Services, Inc. Full time

    Job DescriptionJob DescriptionPremier provider of IT Solutions throughout the southeast is seeking a Cyber Security Analyst / Engineer to become an integral part of our team!We are looking for a Cyber Security Analyst / Engineer to secure, maintain, and support our growing client base's technology infrastructures. You will be part of a systems...


  • Charlotte, United States Motion Recruitment Full time

    We are working with a company that is leading in the field of online education and e-learning solutions. It offers a comprehensive range of services and products designed to enhance learning experiences for individuals, educational institutions, and corporate organizations. As an e-learning company, they specialize in creating and delivering digital learning...