Consultant - Application Security Penetration Tester | Remote US
United States
Full Time USD 64K - 112K
Coalfire
Coalfire is the cybersecurity advisor that combines extensive cloud expertise, technology, and innovative approaches to help clients develop scalable…What You'll Do
- Work independently and collaboratively with a team to both lead and support engagements
- Application Penetration Testing (Browser-based, API, Mobile, IoT, Cloud)
- Threat Modeling
- Source Code Reviews
- Advise clients on technical security or compliance activities.
- Manage priorities and tasks to achieve utilization targets.
- Operate with professionalism both internally and with clients.
- Ensure quality reports and services are delivered efficiently and on time.
- Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables
- Communicate with client stakeholders to include leadership, systems and network administrators, security engineers, development, and support teams.
- Enhance and maintain cloud service provider technical testing methodologies and standards.
- Lead and support penetration testing projects through their entirety.
- Contribute to thought leadership initiatives through blogs, conference speaking, and/or R&D functions.
What You'll Bring
- Proven track record of success managing client engagements.
- A thorough understanding of the Secure Development Life Cycle
- A working knowledge of popular web technologies and languages such as .NET, Java EE, Node.js, Rails or JavaScript
- Working knowledge of web service protocols and hosting technologies
- Familiarity with code scanning and dynamic analysis tools
- Application penetration testing and assessment tradecraft and methodologies (including browser-based, API, thick client, and mobile testing)
- Strong working knowledge of at least two programming or scripting languages, and the ability to read code regardless of the language in which it is written
- Excellent verbal and written communication skills, including technical writing of assessment reports, presentations, and operating procedures
- Client-centric consulting with high level of collaboration
- Strong understanding of security principles, policies, and industry best practices
- Ability to travel up to 10% (potentially & during normal circumstances)
Bonus Points
- Experience in a consulting/professional services role.
- Experience in Application Security and/or Software Development
- Cloud Service penetration testing tradecraft and methodologies across one or more service providers (e.g. AWS, GCP, etc.).
- Familiarity with DevOps engineering concepts, infrastructure automation, pipelines, version control, and deployment strategies are also a plus.
- Deep, progressive experience with AWS security concepts, including IAM, STS, and AWS specific security controls and security architecture design patterns. Professional-level AWS certifications (SAP/DEP), or AWS Specialty certifications with supporting professional experience. Experience with server-less design concepts and supporting services including S3, SQS, SNS, CloudFront, DynamoDB, Lambda and, API Gateway.
- Knowledge of advanced/niche AWS services, including Cognito, IoT Core, or SageMaker are a major plus.
- Mobile platform penetration testing tradecraft and methodologies across widely-used platforms (iOS and/or Android).
- Microservices testing
- Experience with DevOps and/or Security Maturity Modelling (e.g. OWASP SAMM)
- Testing IoT devices and software
- Network/host-based penetration testing tradecraft and methodologies.
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. A reasonable estimate of the compensation range for this role is $64,000 to $112,000 based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
#LI-Remote#LI-GB1
Tags: Android API Gateway APIs Application security Automation AWS Cloud CloudFront Compliance DevOps DynamoDB GCP IAM iOS Java JavaScript Lambda Microservices Node.js OWASP Pentesting R&D S3 SAMM SAP Scripting SNS SQS Travel
Perks/benefits: Career development Competitive pay Conferences Equity Flex hours Flex vacation Health care Insurance Parental leave Salary bonus Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Principal Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Staff Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Product Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Cyber Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Chief Information Security Officer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Senior Penetration Tester jobs
- Open Cybersecurity Specialist jobs
- Open Security Researcher jobs
- Open Senior Security Architect jobs
- Open IT Security Engineer jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Application security-related jobs
- Open Agile-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open Malware-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open Forensics-related jobs
- Open EDR-related jobs
- Open CEH-related jobs
- Open Kubernetes-related jobs