Current jobs related to Penetration Tester - Salem - International Solutions Group
-
Lead Cybersecurity Specialist
4 weeks ago
Salem, Oregon, United States Lumen Inc Full timeAbout LumenLumen is a leading provider of cybersecurity solutions, connecting the world through secure and reliable networks. Our team of experts is dedicated to delivering innovative security solutions that protect our customers' assets and data.The RoleWe are seeking a highly skilled Lead Penetration Tester to join our team. As a Lead Penetration Tester,...
Penetration Tester
2 months ago
Salem, United States
International Solutions Group
Full time
About ISGInternational Solutions Group (ISG) An award-winning IT services company. Our company corporate office is based in Herndon, VA with offices in all major cities across the United States. We have been a trusted partner to some of the world s biggest companies for almost 22 years. At ISG we provide high-quality solutions in several areas of IT and build customized solutions for our clients. Here is our open requirement which can be filled immediately. Kindly respond to this requirement with your contact info and required details to speed up the interview process. Job Title: Penetration TesterLocation: Salem, ORExperience Level: 8+ Years (relevant)Full Time Key Responsibilities / Required Skills: - Experience in manual penetration testing, particularly in web and mobile applications.
- Strong understanding of security frameworks like OWASP Top 10 and NIST Standards.
- Proficiency in using security tools like Burp Suite, ZAP, Metasploit, Checkmarx, and AppScan.
- Hands-on experience with DAST and SAST tools such as IBM AppScan, HP WebInspect, and Acunetix
- Practical experience with AWS services (EC2, S3, KMS, RDS) and security best practices relevant to cloud environments.
- Familiar with Azure cloud security architecture, VNets, and Azure DevOps pipelines.
- Proficient in Python, Perl, PHP, Java, and Objective C for security testing and code reviews.
- Knowledge of core networking concepts like routing, ACLs, SSL/TLS, TCP protocols, and load balancing strategies.
- Experience in building and assessing API security frameworks and secure coding practices for web apps.
- Deep experience in implementing Secure Software Development Life Cycle (S-SDLC) processes, ensuring security across development, testing, and production phases.
- Active participation in platforms like Hack the Box, Portswigger Academy, or Capture the Flag (CTF)
- Passion for discovering new vulnerabilities and security exploits.
- Excellent written and verbal communication skills to clearly articulate security risks and remediation strategies.
- Familiar with common technology stacks such as LAMP, LEMP, and MEAN, as well as secure coding practices for these environments.
- Conduct penetration testing on web and mobile applications, identifying critical vulnerabilities and collaborating with development teams to resolve them.
- Implement and maintain Application Security Programs (DAST & SAST), ensuring all applications follow security best practices.
- Lead security scoping calls with stakeholders, outline security risks, and develop remediation plans.
- Perform code reviews to detect vulnerabilities and enforce secure coding standards, especially in
- Utilize tools such as Burp Suite and Checkmarx for security testing, as well as manual testing for identifying issues like XSS, SQLi, CSRF, etc.
- Provide feedback on application architecture regarding network security, SSL/TLS configurations, and cloud security best practices.
- Stay updated on emerging security vulnerabilities, develop API security strategies, and integrate security controls into the CI/CD pipeline.
- Education:
- Bachelor s degree in Computer Science, Information Technology, Finance, or a related field.
- Benefits:
- Standard company policy.
Thanks & Regards,
Ravinder Shripurostham
International Solutions Group, Inc.
E-mail:
Direct: | x 213