Senior Penetration Tester

1 week ago


New York, United States Northwestern Mutual Full time

At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference.

Principal Accountabilities:

The principal accountability of a Sr. Penetration Tester is to secure the data and information systems of Northwestern Mutual and its policy owners. While pen testers think like an attacker, they will always act with integrity and never abuse their privileges. All work is in service of two primary internal customers:

the Business Owners accountable for the people, processes, and technologies in the organization, and (2) the Blue team accountable for logging, monitoring, and incident response.

The Sr. Penetration Tester serves the Business Owners by identifying, assessing, and responsibly reporting all vulnerabilities discovered throughout the organization. The primary goal being a focus on risk mitigation – allowing for business continuity, but without negligent risk.

The Sr. Penetration Tester serves the Blue Team by simulating threats against which they can engineer detection rules and validate monitoring, alerting, and response capabilities. This partnership happens in an open, knowledge-sharing environment to facilitate timely detection of existing gaps and new attack techniques.

Essential Job Duties:

Penetration Testing: The Senior penetration tester will be accountable for working independently with cross-functional teams to serve as the subject matter expert in the security testing space and independently performing web, mobile, cloud, and network penetration tests in an enterprise environment.

Red Team: Accountable for assisting in the design and implementation of red team exercises including independently leading components of the exercise.

Purple Team: The Senior Penetration Tester will play an active role in the team's purple team program and activities including designing, organizing, and executing purple team engagements and automation.

Leadership: The Senior Penetration Tester is a leader within the Security Testing team with the expectation to guide and mentor more junior members. This includes overseeing the testing performed by junior testers, mentoring their technical educational activities, freely sharing knowledge and testing techniques.

Infrastructure & Automation: Accountable for building, managing, and maintaining security tools and infrastructure that support the security testing team. Focus on designing and implementing automation to aid the team in creating efficiencies for both security testing and threat simulation.

Security Research: Accountable for regularly monitoring the security community for, and researching, the latest assessment and exploit methodologies. This phase of the work is concluded by sharing the information back to the team in the form of newly written tools and/or attack techniques via informal internal training sessions.

Test Coordination: Accountable for coordinating with internal team members to ensure that scheduled tests include all information needed to perform a successful penetration test.

Reporting: Accountable for preparing and delivering the highest quality security information that comprehensively and clearly explains risk, demonstrates findings, and offers tactical and strategic recommendations to both technical and non-technical internal clients.

Communication: Effective and professional communication of a variety of topics, including technical and non-technical information, to a wide variety of internal and external customers including leadership from across the organization.

Bug Bounty: Accountable for high-level management of bug bounty program including validation of bug submissions.

Ad Hoc Incidents: Accountable for working with security architects, the security operations center, incident responders, and technology infrastructure, and development teams, as necessary.

Metrics: Accountable for working with select team members to track, monitor, and report testing results in a meaningful way so that risk-based security metrics are delivered to the enterprise.

Training: Attend training to stay current with technology and security trends. Perform other duties as assigned.

Requirements:

  • Proficiency with both Windows and Linux operating systems. Including advanced command line skills.
  • Thorough command of web application design principles in the areas of coding, infrastructure, middleware, etc.
  • Thorough command of each of the following security assessment suites: Burp Suite, Wireshark, and tcpdump in addition to some experience with one or more adversarial simulation platform such as Cobalt Strike, Brute Ratel, Sliver, Mythic, etc.
  • Thorough command of applicable frameworks including the “OWASP Top Ten” and MITRE ATT&CK.
  • Thorough command of the OSI Model, web, and network protocols such as TCP, UDP and HTTP/S.
  • Competency with one or more scripting/programming languages such as Python, JavaScript, Java, Ruby, Go, PowerShell, Bash, C#, C/C++, etc.
  • Experience with applications hosted in Amazon Web Services (AWS) and/or Microsoft Azure, preferably within an Agile/DevOps operating model.
  • Experience with Amazon Web Services (AWS) and/or Microsoft Azure platforms and the associated security implications.
  • Thorough command of APIs and associated protocols, such as JSON, REST, or SOAP.
  • Ability to analyze attack techniques and create custom, or repurpose existing, tooling to perform the attacks.
  • Thorough understanding of cryptography controls and underlying concepts to secure data.
  • Thorough command of defense-in-depth design and operational concerns.
  • Strong ability to independently identify and resolve critical and complex issues through effective critical thinking skills.
  • History of acting with integrity, taking pride in work, seeking to excel, being curious, and adaptable.
  • Ability to maintain and strengthen relationships; ability to effectively influence and negotiate with internal and external partners.
  • Proven interpersonal savvy with demonstrated tact and diplomacy.
  • Strong written and verbal communication skills with the ability to interpret and fully explain the impact of vulnerabilities as well as any recommended remediation to multiple knowledge levels.

Desirable:

  • One or more advanced certifications in penetration testing (e.g., GWAPT, GPEN, GMOB, Offensive Security certs).
  • 5+ years’ experience performing security testing activities such as web, mobile, or infrastructure/network testing.
  • 5+ years’ experience with one or more of the following security assessment suites: Cobalt Strike, Brute Ratel, Mythic, Sliver etc.
  • 5+ years’ experience with one or more scripting/programming languages such as Python, JavaScript, Java, Ruby, Go, PowerShell, Bash, C#, C/C++, etc.
  • Formal software development experience preferred but not necessarily required.
  • Experience automating Amazon Web Services (AWS) and/or Microsoft Azure platform infrastructure, preferably within an Agile/DevOps operating model.
  • Public bug bounty profile (BugCrowd or HackerOne) with a record of bug submissions, or similar public record of coordinated bug disclosures.
  • Proven people leadership skills, formal or informal, including the ability to manage small teams and small projects.
  • Ability to be a leader in the security industry demonstrated by participation organizing and/or contributing to conferences by giving talks.

Experience Requirements:

  • Bachelor’s degree with an emphasis in Computer Science, Computer Engineering, Software Engineering, MIS, or related field.
  • Highly technical and analytical hands-on experience in prior professional roles.
  • 3-5 years of experience with web/mobile application and/or network penetration testing or proven capabilities in other required skills including independent security research, CTF events, bug bounty programs, etc.

Our Benefits

  • Highly competitive compensation, including annual bonus opportunities.
  • Medical/Dental/Vision plans, 401(k), pension program
  • Tuition reimbursement, commuter plans, and paid time off
  • Extensive Professional Training Opportunities
  • Excellent Work/Life Balance

Compensation Range:

Pay Range - Start:

$110,040.00

Pay Range - End:

$204,360.00

Northwestern Mutual pays on a geographic-specific salary structure and placement in the salary range for this position will be determined by a number of factors including the skills, education, training, credentials and experience of the candidate; the scope, complexity as well as the cost of labor in the market; and other conditions of employment. At Northwestern Mutual, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. Please note that the salary range listed in the posting is the standard pay structure. Positions in certain locations (such as California) may provide an increase on the standard pay structure based on the location. Please click here for additional information relating to location-based pay structures.

Job Posting End Date:

The timeline for this job posting may be shortened or extended based on organizational needs

Grow your career with a best-in-class company that puts our client’s interests at the center of all we do. Get started now

We are an equal opportunity/affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender identity or expression, sexual orientation, national origin, disability, age or status as a protected veteran, or any other characteristic protected by law.

If you work or would be working in California, Colorado, New York City, Washington or outside of a Corporate location, please click here for information pertaining to compensation and benefits.



  • New Brighton, Minnesota, United States TÜV SÜD America Full time

    Job DescriptionOur team at TÜV SÜD America is seeking a skilled Cybersecurity Penetration Tester to join our ranks.Job Summary:This role is responsible for conducting penetration testing, vulnerability assessments, and security code reviews to identify weaknesses in medical devices and applications.Key Responsibilities:Perform thorough penetration testing,...

  • Automation Tester

    4 months ago


    New York, United States CapB InfoteK Full time

    We are looking for an Automation Tester for our long-term multiyear project in NY (Remote till pandemic). 1. QA resources with Captital Market/Trading domian experience 2. Hands on knowledge on Agile Process and Work Flows 3. Techno-Functional with experience in UI automation (Selenium/JAVA), Database quering, Mainframe and UNIX 4. Intermidate/Senior Level...


  • New York, New York, United States Planet Technology Full time

    We are seeking an experienced Senior Quality Assurance Expert to join our team at Planet Technology in NYC.As a Senior Quality Assurance Expert, you will be responsible for ensuring the highest quality of our software products. This is a 6+ month contracting role, which requires you to be local in NYC and not require sponsorship at any point.Must haves:No...


  • New York, New York, United States WuXi AppTec Full time

    The Senior Manager, Business Development drives sales growth in close coordination with WuXi Biology leadership. This role is responsible for penetrating certain assigned customers with significant growth opportunity, as assigned by management.Key ResponsibilitiesClose and implement growth opportunities with Companies in their region.Closely work with the...


  • New York, United States Metropolitan Jewish Health System Full time

    Our Corporate team may not provide direct care, but we still touch people's lives in a very real and substantial way. The services we provide contribute greatly to the overall patient and member experience, supporting our reputation for excellence. The Senior Information Security Analyst will have strong technical experience and a risk evaluation mindset in...


  • New York, United States Metropolitan Jewish Health System Full time

    Our Corporate team may not provide direct care, but we still touch people's lives in a very real and substantial way. The services we provide contribute greatly to the overall patient and member experience, supporting our reputation for excellence. The Senior Information Security Analyst will have strong technical experience and a risk evaluation mindset in...


  • New York, United States Pride Health Full time

    Job Title: Senior Technologist Laboratory Location: New York, NY 10065 Pay : $53-$56(hourly) Shift: Day Shift Start Date: ASAPClinical Lab Scientist - Cytogenetics. Strong karyotyping skills, specifically oncology experience. 2 or more years of karyotyping experience. Expected to perform wet lab work.ASCP is preferred.NYS Clinical Laboratory Technologist...


  • New York, United States InterSources Full time

    Job Title: Senior Application Security Engineer Work Location: New York, NY Duration: 12 months contractPosition Summary: Hours: THIS POSITION WILL ALLOW 35.00 - HOURS PER WEEKMANDATORY SKILLS/EXPERIENCE 12 years of experience in application security, with a proven track record of conducting vulnerability assessments, penetration testing, and secure code...


  • New York, New York, United States Curenta Full time

    Curenta is seeking a highly motivated Sales Director to lead sales efforts in the senior care sector. This role is critical in driving revenue growth, building strong relationships with senior care providers, and positioning our SaaS solutions as essential tools for improving patient outcomes and operational efficiency.Job Overview:We are looking for a...


  • New York, New York, United States Canon Solutions America, Inc. Full time

    Job OverviewWe are seeking an experienced Senior Business Development Manager to join our team at Canon Solutions America, Inc. in New York.About the RoleThis is a fantastic opportunity to leverage your sales skills and knowledge of office technology to drive business growth and success. As a Senior Business Development Manager, you will be responsible for...


  • New York, New York, United States WTW inc. Full time

    {"Job Title: Global Benefits Consultant LeadAt WTW, we are looking for a highly skilled and experienced professional to lead our Global Benefits Consulting team. The ideal candidate will have a proven track record of success in managing large client relationships and leading global teams.Key Responsibilities:Develop and implement global benefits strategies...


  • New York, United States Schonfeld Full time

    Senior Cybersecurity Analyst The Role The Schonfeld Cybersecurity Operations Team is looking for individuals who are excited by the idea of finding threats in ways no other defense mechanism can, eradicating threats, and building new intelligence to prevent future attacks from succeeding. This Senior Cybersecurity Analyst will be responsible for improving...


  • New York, New York, United States Ashton Lane Group, Inc Full time

    Job TitleFintech Senior Product ManagerAbout the RoleWe are seeking an experienced Fintech Senior Product Manager to lead our product development efforts and drive innovation in our wealth-tech firm.ResponsibilitiesProduct Leadership: Lead one or more advisor portal squads through the ideation, technical development, and launch of innovative products.Team...


  • New York, New York, United States RIT Solutions, Inc. Full time

    RIT Solutions, Inc. is currently seeking a skilled Senior Quality Assurance Specialist to join our team in Dallas, TX; New York, NY; or Salt Lake City, UT.About the RoleWe are looking for an experienced QA Tester to work on a Top-Tier Investment Bank project. The ideal candidate will have advanced proficiency in writing, executing, and maintaining automated...


  • New York, United States Metropolitan Jewish Health System Full time

    Overview: Our Corporate team may not provide direct care, but we still touch people's lives in a very real and substantial way. The services we provide contribute greatly to the overall patient and member experience, supporting our reputation for excellence. Why work for MJHS?: When you work with us you will receive comprehensive and affordable health and...


  • New York, New York, United States Applause Full time

    Unlock Business Growth with ApplauseAmbitious sales professionals are sought by Applause, a world leader in digital quality testing, to drive revenue expansion across the Financial Services industry. As a key member of our team, you will be responsible for cultivating and maintaining strategic client relationships, identifying opportunities for up-selling...


  • New York, New York, United States Updater Full time

    Job SummaryWe are seeking an experienced Senior Manager, Quality Assurance to drive the evolution of our quality assurance practices and lead a team of manual testers and SDETs.About UpdaterUpdater is a leading provider of moving services, helping millions of households relocate every year in the US. Our innovative platform seamlessly forwards mail,...


  • New York, United States Diverse Lynx Full time

    Senior Salesforce Developer Milwaukee, WI Type : Full Time/ Permanent Job Description Must-Have** (Ideally should not be more than 3-5) 7+yrs in Salesforce development, Technical Design and Implementation - Technical Hands-on knowledge in Lightning Aura, Lightning web component Design and Development - Depth in Salesforce APEX development -...


  • New York, United States Diverse Lynx Full time

    Senior Salesforce Developer Milwaukee, WI Type : Full Time/ Permanent Job Description Must-Have** (Ideally should not be more than 3-5) 7+yrs in Salesforce development, Technical Design and Implementation - Technical Hands-on knowledge in Lightning Aura, Lightning web component Design and Development - Depth in Salesforce APEX development -...


  • New York, New York, United States SIXT USA Full time

    About the RoleWe are seeking an accomplished Senior Branch Manager to oversee the operations of multiple branches, driving sales performance and ensuring exceptional customer service.Based in New York, United States, this key leadership position is responsible for managing budgets, sales targets, and market penetration across various branch locations.