Senior Penetration Tester

3 days ago


Milwaukee WI United States Northwestern Mutual Full time
At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference.

Principal Accountabilities:

The principal accountability of a Sr. Penetration Tester is to secure the data and information systems of Northwestern Mutual and its policy owners. While pen testers think like an attacker, they will always act with integrity and never abuse their privileges. All work is in service of two primary internal customers:

the Business Owners accountable for the people, processes, and technologies in the organization, and (2) the Blue team accountable for logging, monitoring, and incident response.

The Sr. Penetration Tester serves the Business Owners by identifying, assessing, and responsibly reporting all vulnerabilities discovered throughout the organization. The primary goal being a focus on risk mitigation allowing for business continuity, but without negligent risk.

The Sr. Penetration Tester serves the Blue Team by simulating threats against which they can engineer detection rules and validate monitoring, alerting, and response capabilities. This partnership happens in an open, knowledge-sharing environment to facilitate timely detection of existing gaps and new attack techniques.

Essential Job Duties:

Penetration Testing: The Senior penetration tester will be accountable for working independently with cross-functional teams to serve as the subject matter expert in the security testing space and independently performing web, mobile, cloud, and network penetration tests in an enterprise environment.

Red Team: Accountable for assisting in the design and implementation of red team exercises including independently leading components of the exercise.

Purple Team: The Senior Penetration Tester will play an active role in the team's purple team program and activities including designing, organizing, and executing purple team engagements and automation.

Leadership: The Senior Penetration Tester is a leader within the Security Testing team with the expectation to guide and mentor more junior members. This includes overseeing the testing performed by junior testers, mentoring their technical educational activities, freely sharing knowledge and testing techniques.

Infrastructure & Automation: Accountable for building, managing, and maintaining security tools and infrastructure that support the security testing team. Focus on designing and implementing automation to aid the team in creating efficiencies for both security testing and threat simulation.

Security Research: Accountable for regularly monitoring the security community for, and researching, the latest assessment and exploit methodologies. This phase of the work is concluded by sharing the information back to the team in the form of newly written tools and/or attack techniques via informal internal training sessions.

Test Coordination: Accountable for coordinating with internal team members to ensure that scheduled tests include all information needed to perform a successful penetration test.

Reporting: Accountable for preparing and delivering the highest quality security information that comprehensively and clearly explains risk, demonstrates findings, and offers tactical and strategic recommendations to both technical and non-technical internal clients.

Communication: Effective and professional communication of a variety of topics, including technical and non-technical information, to a wide variety of internal and external customers including leadership from across the organization.

Bug Bounty: Accountable for high-level management of bug bounty program including validation of bug submissions.

Ad Hoc Incidents: Accountable for working with security architects, the security operations center, incident responders, and technology infrastructure, and development teams, as necessary.

Metrics: Accountable for working with select team members to track, monitor, and report testing results in a meaningful way so that risk-based security metrics are delivered to the enterprise.

Training: Attend training to stay current with technology and security trends. Perform other duties as assigned.

Requirements:

  • Proficiency with both Windows and Linux operating systems. Including advanced command line skills.
  • Thorough command of web application design principles in the areas of coding, infrastructure, middleware, etc.
  • Thorough command of each of the following security assessment suites: Burp Suite, Wireshark, and tcpdump in addition to some experience with one or more adversarial simulation platform such as Cobalt Strike, Brute Ratel, Sliver, Mythic, etc.
  • Thorough command of applicable frameworks including the OWASP Top Ten and MITRE ATT&CK.
  • Thorough command of the OSI Model, web, and network protocols such as TCP, UDP and HTTP/S.
  • Competency with one or more scripting/programming languages such as Python, JavaScript, Java, Ruby, Go, PowerShell, Bash, C#, C/C++, etc.
  • Experience with applications hosted in Amazon Web Services (AWS) and/or Microsoft Azure, preferably within an Agile/DevOps operating model.
  • Experience with Amazon Web Services (AWS) and/or Microsoft Azure platforms and the associated security implications.
  • Thorough command of APIs and associated protocols, such as JSON, REST, or SOAP.
  • Ability to analyze attack techniques and create custom, or repurpose existing, tooling to perform the attacks.
  • Thorough understanding of cryptography controls and underlying concepts to secure data.
  • Thorough command of defense-in-depth design and operational concerns.
  • Strong ability to independently identify and resolve critical and complex issues through effective critical thinking skills.
  • History of acting with integrity, taking pride in work, seeking to excel, being curious, and adaptable.
  • Ability to maintain and strengthen relationships; ability to effectively influence and negotiate with internal and external partners.
  • Proven interpersonal savvy with demonstrated tact and diplomacy.
  • Strong written and verbal communication skills with the ability to interpret and fully explain the impact of vulnerabilities as well as any recommended remediation to multiple knowledge levels.

Desirable:

  • One or more advanced certifications in penetration testing (e.g., GWAPT, GPEN, GMOB, Offensive Security certs).
  • 5+ years experience performing security testing activities such as web, mobile, or infrastructure/network testing.
  • 5+ years experience with one or more of the following security assessment suites: Cobalt Strike, Brute Ratel, Mythic, Sliver etc.
  • 5+ years experience with one or more scripting/programming languages such as Python, JavaScript, Java, Ruby, Go, PowerShell, Bash, C#, C/C++, etc.
  • Formal software development experience preferred but not necessarily required.
  • Experience automating Amazon Web Services (AWS) and/or Microsoft Azure platform infrastructure, preferably within an Agile/DevOps operating model.
  • Public bug bounty profile (BugCrowd or HackerOne) with a record of bug submissions, or similar public record of coordinated bug disclosures.
  • Proven people leadership skills, formal or informal, including the ability to manage small teams and small projects.
  • Ability to be a leader in the security industry demonstrated by participation organizing and/or contributing to conferences by giving talks.

Experience Requirements:

  • Bachelors degree with an emphasis in Computer Science, Computer Engineering, Software Engineering, MIS, or related field.
  • Highly technical and analytical hands-on experience in prior professional roles.
  • 3-5 years of experience with web/mobile application and/or network penetration testing or proven capabilities in other required skills including independent security research, CTF events, bug bounty programs, etc.

Our Benefits

  • Highly competitive compensation, including annual bonus opportunities.
  • Medical/Dental/Vision plans, 401(k), pension program
  • Tuition reimbursement, commuter plans, and paid time off
  • Extensive Professional Training Opportunities
  • Excellent Work/Life Balance

Compensation Range:

Pay Range - Start:

$110,040.00

Pay Range - End:

$204,360.00

Northwestern Mutual pays on a geographic-specific salary structure and placement in the salary range for this position will be determined by a number of factors including the skills, education, training, credentials and experience of the candidate; the scope, complexity as well as the cost of labor in the market; and other conditions of employment. At Northwestern Mutual, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. Please note that the salary range listed in the posting is the standard pay structure. Positions in certain locations (such as California) may provide an increase on the standard pay structure based on the location. Please click here for additional information relating to location-based pay structures.

Job Posting End Date:

The timeline for this job posting may be shortened or extended based on organizational needs

Grow your career with a best-in-class company that puts our clients interests at the center of all we do. Get started now

We are an equal opportunity/affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender identity or expression, sexual orientation, national origin, disability, age or status as a protected veteran, or any other characteristic protected by law.

If you work or would be working in California, Colorado, New York City, Washington or outside of a Corporate location, please click here for information pertaining to compensation and benefits.


FIND YOUR FUTURE

Were excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and commitment to diversity and inclusion.

  • Flexible work schedules
  • Concierge service
  • Comprehensive benefits
  • Employee resource groups
PandoLogic. Keywords: Hacker, Location: Milwaukee, WI - 53205RequiredPreferredJob Industries
  • Customer Service


  • Milwaukee, United States NORTHWESTERN MUTUAL LIFE INSURANCE Full time

    JOB REQUIREMENTS: At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference. Principal Accountabilities: The principal accountability of a Sr. Penetration Tester is to secure the data and information systems of Northwestern Mutual and its policy owners. While pen testers think like an...


  • Milwaukee, WI, United States Northwestern Mutual Full time

    At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference. Principal Accountabilities: The principal accountability of a Sr. Penetration Tester is to secure the data and information systems of Northwestern Mutual and its policy owners. While pen testers think like...


  • Milwaukee, United States Northwestern Mutual Full time

    At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference. Principal Accountabilities: The principal accountability of a Sr. Penetration Tester is to secure the data and information systems of Northwestern Mutual and its policy owners. While pen testers think like an attacker, they will...

  • Penetration Tester

    3 weeks ago


    San Francisco, CA, United States University of California - San Francisco Full time

    Penetration Tester PPH-Domestic-Core-IZ Full Time 82263BR Job Summary We are seeking an experienced Penetration Tester specializing in web application testing. The incumbent will be responsible for conducting comprehensive assessments of our web applications to identify vulnerabilities and improve security. This position supports the California Immunization...

  • Penetration Tester

    3 weeks ago


    Honolulu, HI, United States Cymertek Corporation Full time

    Penetration Tester KEY SUMMARY We are seeking a highly skilled and proactive Penetration Tester to join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems by simulating real-world attacks. You will collaborate with teams to develop actionable recommendations, enhance security...


  • Washington, DC, United States Chenega Corporation Full time

    Intermediate Penetration Tester Hybrid Schedule: In person, in the Washington, DC office twice per week Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega Military, Intelligence &...


  • Herndon, VA, United States Booz Allen Full time

    Cyber Security Engineer and Penetration TesterKey Role:Find possible vulnerabilities while using penetration testing tools and techniques to ensure the security of computer systems, applications, servers, and networks. Apply advanced consulting skills, extensive technical expertise, and full industry knowledge. Develop innovative solutions to complex...


  • Merrimack, NH, United States Fidelity TalentSource LLC Full time

    Job Description:Senior Cybersecurity Penetration TesterThe RoleThe mission of the penetration testing team is to protect Fidelity's assets and our customers livelihoods from the threat of exploitation by malicious adversaries.u00A0The penetration testing team does this by proactively identifying vulnerabilities in our systems and serving as subject matter...


  • Milwaukee, Wisconsin, United States Compunnel Inc. Full time

    Compunnel Inc. is seeking a skilled Senior Automation Tester to join our team in Milwaukee, WI. We offer a competitive salary of $120,000 per year.Job DescriptionWe are looking for a highly motivated and experienced Senior Automation Tester to play a key role in our test automation team. The ideal candidate will have strong JavaScript skills and experience...


  • Woburn, MA, United States Randstad Digital Full time

    Senior Software Quality Assurance Tester for Randstad Digital, LLC. Are you the right candidate for this opportunity Make sure to read the full description below. Multiple openings. Headquarters: Woburn, MA. Conduct end-to-end, regression, and performance software and application testing to meet business, technical, and functional requirements. Develop...


  • , MD, United States Hirebridge Full time

    This job opportunity is part of an RFP process; candidates are invited to submit their resumes detailing relevant experience. Location: Bethesda, MD (Hybrid) LCG is a minority-owned technology consulting firm that has been a trusted partner to more than 40 federal agencies, including 21 of the 27 Institutes and Centers (ICs) at the National Institutes of...


  • Washington, DC, United States Amazon Full time

    Security Engineer II, Offensive Security Penetration Testing Job ID: 2817030 | Amazon.com Services LLC Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them...


  • Boston, MA, United States Ryder System, Inc. Full time

    Summary The Senior IT QA Automation Tester is responsible for ensuring the quality and reliability of software products through meticulous testing and analysis in a multi-product microservice architecture. This role leads testing efforts by designing, implementing, and executing test plans, test cases, and test automation frameworks in an Agile and...

  • Senior Test Lead

    2 weeks ago


    Milwaukee, Wisconsin, United States Northwestern Mutual Full time

    We are seeking a talented and experienced Senior Test Lead to join our engineering team at Northwestern Mutual. As a key member of our team, you will oversee end-to-end testing efforts and guide us towards standardized best practices. Your leadership and expertise will ensure our testing methodologies are robust and consistent, significantly contributing to...


  • Washington, DC, United States JPMorgan Chase & Co. Full time

    Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...


  • Milwaukee, United States Diverse Lynx Full time

    Role - Senior Salesforce Developer Location - Milwaukee, WI Duration - Full Time Job Description Must-Have** (Ideally should not be more than 3-5) 7+yrs in Salesforce development, Technical Design and Implementation - Technical Hands-on knowledge in Lightning Aura, Lightning web component Design and Development - Depth in Salesforce APEX development -...


  • Milwaukee, United States KOMATSU AMERICA Full time

    JOB REQUIREMENTS: Komatsu is an indispensable partner to the construction, mining, forestry, forklift, and industrial machinery markets, maximizing value for customers through innovative solutions. With a diverse line of products supported by our advanced IoT technologies, regional distribution channels, and a global service network, we tap into the power of...


  • Milwaukee, Wisconsin, United States TEKsystems Full time

    At TEKsystems, we are seeking a highly skilled Senior Cabling Specialist to join our team.Job Summary:We are looking for a technical expert with extensive experience in cabling systems installation and maintenance. The ideal candidate will have a strong background in fiber optic cable termination, copper cable installations, and data cable termination.About...


  • Milwaukee, Wisconsin, United States NORTHWESTERN MUTUAL LIFE INSURANCE Full time

    About the RoleWe are seeking a highly skilled Enterprise Security Specialist to join our team at Northwestern Mutual Life Insurance. This is a senior-level position that requires extensive experience in penetration testing, red team exercises, and purple team engagements.ResponsibilitiesPerform web, mobile, cloud, and network penetration tests in an...


  • Minneapolis, MN, United States GoTo Full time

    GoTo Businesses of all sizes trust GoTo to power business growth and support customers. Explore our business phone system, contact center, and IT support products. View all jobs at GoTo Where you’ll work: Anywhere within Hungary Offensive Security at GoTo The Offensive Security team conducts various security assessments in a variety of domains;...