Job Closed
This listing is no longer active.
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.
Security Analyst, Penetration Testing
Location
United States
Posted
121 days ago
Salary
$89.3K - $120.8K / year
Seniority
Senior
Job Description
Security Analyst, Penetration Testing
Rapid7
• Perform technical testing against a variety of targets, including network penetration testing (internal, external, and wireless), web application and API testing, and social engineering (on-premise and electronic) • Consistently produce high-quality reports and peer-review colleagues' work for errors and inaccuracies • Help develop and create Executive Briefings • Deliver timely reports to clients and external stakeholders • Translate technical concepts and convey them to non-security personnel • Be capable of learning in a fast-paced environment and taking on solo engagements • Participate in industry conferences and professional organizations
Job Requirements
- 3+ years in an active technical security role
- Excellent written and verbal communication skills
- Previous technical security consulting experience
- Knowledge of modern penetration testing tools and methods
- Strong knowledge of network, web-based application, and IEEE 802.11 security concepts
- Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite
- Experience using interpreted languages (Ruby, Python, PHP, etc.) and knowledge of compiled languages (Java, C, C++, Assembly, etc.)
- Experience with social engineering techniques and tactics
- Bachelor’s degree in Computer Science, MIS, CIS or a related field, or equivalent experience
- Certifications such as GPEN, CPTS, or OSCP.
Benefits
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Ensure platform, applications, and infrastructure compliance and security • Assist with security efforts and audits for compliance requirements • Work with various teams to implement best practices • Assess and manage risks on identified vulnerabilities • Provide compliance assessments and audits for business units • Lead and facilitate penetration testing and auditing efforts
• Work with Team to develop a strategy and timeline to meet each project’s milestones and deliverables.. • Participate in the network design, security architecture, and development of diagrams. • Participate in hardware, software, communications media specification. • Participate in device configurations and hardening for security compliance and risk management. • Work with Team to ensure timely delivery of high-quality cybersecurity documentation including diagrams, configuration guides, and training materials. • Participate in cybersecurity assessments including vulnerability and compliance scans and reports. • Participate in S&C’s Information Security program as it applies to customer-facing services. • Perform advanced networking tasks including configuration, troubleshooting, and optimization of Cisco routers, switches, firewalls, and related technologies to support secure communication architectures.
• Manage Plan of Action & Milestones (POA&Ms) lifecycle including creation, tracking, risk adjustment justification, and deviation requests in coordination with 3PAO assessors and federal stakeholders • Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with FedRAMP, HITRUST, PCI, and similar frameworks • Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries • Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments • Translate technical vulnerability findings into risk-based language for federal clients and authorization officials, presenting monthly status briefings as needed • Collaborate with development, SRE, and infrastructure teams to integrate vulnerability management into CI/CD pipelines, cloud environments (AWS, Azure, GCP), and container/Kubernetes platforms • Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture • Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches • Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation • Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates for clients • Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures
• Conduct our digital risk management program to improve cybersecurity. • Plan, support, and execute security awareness training campaigns. • Assist with analysis, communication, and documentation of audits. • Undertake compliance program/project initiatives, audits, and benchmarking of security policies against good practice and standards. • Assist in the development and implementation of sustainable compliance framework and processes in the organization to meet IT policies, business requirements, and applicable legal and regulatory requirements. • Gain widespread support of and compliance with information security requirements. • Address vulnerabilities identified from various scans making sure that they are properly addressed and categorized leading in the corrective actions to assure data and infrastructure security. • Assist with SOX compliance testing as required




