LEAD PENETRATION TESTER

4 weeks ago


New York, United States Capital One Full time
Center 3 (19075), United States of America, McLean, Virginia

Lead Penetration Tester (Remote-Eligible)

Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan, coordinate, execute and report on sophisticated ethical hacking exercises, to identify cyber vulnerabilities and reduce the risk posture of enterprise systems. This role will be responsible for the identification and exploitation of security weaknesses, providing actionable recommendations, and collaborating with various teams to enhance our security posture.

The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One?s information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats.

Primary responsibilities for this position include

  • Perform penetration testing of enterprise networks, services, applications, and infrastructure.

  • Develop automation and tooling to enhance the capabilities of the Offensive Security team.

  • Assess Capital One?s development practices and help drive corporate security standards.

  • Work with developers on remediation guidance and improvements throughout the Software CI/CD pipeline.

Capital One is open to hiring a Remote Employee for this opportunity.

Basic Qualifications:

  • High School Diploma, GED or equivalent certification

  • At least 5 years of experience working in cybersecurity or information technology

  • At least 4 years of Penetration Testing experience

  • At least 2 years of experience with public cloud environments (AWS, Azure, Google Cloud Platform)

  • At least 1 year of experience in Python, Golang, or C#

Preferred Qualifications:

  • Bachelor's Degree

  • 5+ years of security testing experience? (red teaming, cloud security, application security, or network security)

  • 5+ years of experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE)

  • Experience developing Offensive Security tools

  • Experience with code review and secure coding standards

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

New York City (Hybrid On-Site): $201,400 - $229,900 for Manager, Cyber Technical

San Francisco, California (Hybrid On-Site): $213,400 - $243,500 for Manager, Cyber Technical

Remote (Regardless of Location): $170,700 - $194,800 for Manager, Cyber Technical

Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate?s offer letter.

This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City?s Fair Chance Act; Philadelphia?s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).



  • New Orleans, United States ExecRecruitment Full time

    Job DescriptionJob DescriptionExecRecruitment is a global professional services provider and contingency staffing company. Our main objective is to source top talent and support professional growth.One of our direct clients is actively seeking a Senior Penetration Tester to join their team.Job Title: Senior Penetration TesterLocation: RemoteDuration: 6...


  • New York, New York, United States WithSecure Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Cybersecurity Consultant to join our team at WithSecure. As a key member of our team, you will be responsible for leading penetration tests and security assessments, as well as representing the company in key client relationships.Key ResponsibilitiesLead penetration tests and security...


  • New York, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Penetration TesterCapital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan,...


  • New York, United States Iceberg Cyber Security Full time

    I’m currently representing an upcoming leader in cybersecurity, providing cutting-edge solutions and testing services. Their current mission is to venture into the world of hardware and embedded testing and they are looking for a leader to join as a principal Embedded Security Tester and develop new offensive security offerings.As an Embedded Security...

  • Lead Tester

    1 week ago


    New York, United States Saxon Global Full time

    Client CVS Position: Lead Tester Visa: No H1 Rate: $50/ hour C2C Fully Remote Contract through 12/31/2024 Candidates are required to take a Glider assessment ASAP upon submittal. I will send out the assessment as soon as you provide your candidate's profile. Glider assessment focuses on: Jmeter Load Test Concept Loadrunner Manual...


  • New York, New York, United States A-1 Consulting Inc, Atlanta, GA Full time

    Are you an experienced Quality Assurance and ETL Tester seeking a new challenge? A-1 Consulting Inc is looking for a Lead QA/ETL Tester with over 13 years of expertise to become a vital part of our dynamic Agile project teams. If you possess a robust background in Database/ETL Processes and Data Warehouse Testing, this role may be an excellent fit for...


  • New York, New York, United States A-1 Consulting Inc, Atlanta, GA Full time

    Are you an experienced Quality Assurance and ETL Tester seeking a new challenge? A-1 Consulting Inc is looking for a Lead QA/ETL Tester with over 13 years of expertise to become a vital part of our dynamic Agile project teams. If you possess a robust background in Database/ETL Processes and Data Warehouse Testing, this opportunity may align perfectly with...


  • New York, United States Iceberg Cyber Security Full time

    I’m currently representing an upcoming leader in cybersecurity, providing cutting-edge solutions and testing services. Their current mission is to venture into the world of hardware and embedded testing and they are looking for a leader to join as a principal Embedded Security Tester and develop new offensive security offerings.As an Embedded Security...

  • Performance Tester

    1 month ago


    New York, United States Pyramid Consulting, Inc Full time

    Immediate need for a talented Performance Tester. This is a 12+ Months Contract opportunity with long-term potential and is located in NYC, NY(Onsite). Please review the job description below and contact me ASAP if you are interested.Job ID:24-35718Pay Range: $50 - $57/hour. Employee benefits include, but are not limited to, health insurance (medical,...

  • Performance Tester

    1 month ago


    New York, United States Pyramid Consulting, Inc Full time

    Immediate need for a talented Performance Tester. This is a 12+ Months Contract opportunity with long-term potential and is located in NYC, NY(Onsite). Please review the job description below and contact me ASAP if you are interested.Job ID:24-35718Pay Range: $50 - $57/hour. Employee benefits include, but are not limited to, health insurance (medical,...

  • QA Tester

    2 months ago


    New York, United States Everplans Full time

    About Everplans Everplans helps you organize, store, and securely share all of your most important information. From your home, to your documents, to your personal decisions. Through a combination of original content, a personalized guidance engine, and an intuitive digital vault, people can say goodbye to sticky notes around the computer, old file folders...

  • QA Tester

    2 months ago


    New York, United States Everplans Full time

    Job DescriptionJob DescriptionAbout EverplansEverplans helps you organize, store, and securely share all of your most important information. From your home, to your documents, to your personal decisions. Through a combination of original content, a personalized guidance engine, and an intuitive digital vault, people can say goodbye to sticky notes around the...

  • Automation QA Lead

    1 day ago


    New York, United States Saxon Global Full time

    Client #5: QA TESTER LEAD POSITION HYBRID - 1 YEAR QA TESTER LEAD POSITION HYBRID In Boston MA - must be local 1 YEAR CONTACT Rate IS OPEN (75-80hr c2c PAY) There is a role in coordinating the test plans that is needed. The functional leads will be responsible for the actual creation of the test scripts Description: 1. Entry and Exit criteria ...


  • New York, United States The Cypress Group Full time

    Job DescriptionJob Descriptionutomated Tester Role - Electronic ExchangeLocation:Lower Manhattan (Hybrid, 3 days a week)Compensation:Up to $200,000 base + Discretionary BonusJob Description:We are seeking an experienced Automated Tester to join our dynamic team at a leading electronic exchange. The ideal candidate will have a strong background in Java, SQL,...


  • New York, United States AGS Cyber Full time

    ClientA fortune 500 global professional services leader who specialise in helping their clients shape business decision for the better.RoleWe are looking for a highly skilled and experienced Director to build, lead, and grow the newly established Hardware Security service line. This pivotal role involves building a new service line from the ground up,...


  • New Brighton, United States TÜV SÜD America Full time

    Job DescriptionJob DescriptionPosition Summary:This position is responsible for focusing domain areas of expertise as well as a good breadth of experience across Application Penetration Testing, Thick Client Penetration Testing, Web Application Penetration Testing, Mobile Application Penetration Testing (iOS and Android), Medical IoT devices Penetration...


  • New York, United States Airitos Full time

    Location: Hybrid Onsite 2-3x / Week in New York, NY Job Type: ~ 1 Year Contract w/Potential for Extension Job Description: Our Application Security team acts as a trusted assessor and risk advisor for the application development teams. The team comprises of security engineers with expertise in software security and penetration testing. We are the go-to...


  • New York, New York, United States S&P Global Full time

    About the RoleThe Data Quality Engineer will play a critical role in ensuring the reliability and performance of our new data platform, which supports various business segments. This position will work in tandem with the Data Engineering team to understand the platform's architecture and contribute to its continuous improvement by rigorously testing data...


  • New York, United States Airitos Full time

    Job DescriptionJob DescriptionLocation: Hybrid Onsite 2-3x / Week in New York, NY Job Type: ~ 1 Year Contract w/Potential for Extension Job Description: Our Application Security team acts as a trusted assessor and risk advisor for the application development teams. The team comprises of security engineers with expertise in software security and...

  • Software Data Tester

    3 months ago


    New York, United States S&P Global Full time

    About the Role : Grade Level (for internal use): 10 The   Role:  Data Quality Engineer The Team:  In the Technology division of Sustainability, we and the businesses we support face a diverse and engaging set of challenges. It follows that bringing diverse and engaged people together is what makes our division successful. Our program is built...