Defeat Cyberattacks
Senior Penetration Testing Analyst
Location
Japan
Posted
75 days ago
Salary
0
Seniority
Senior
Job Description
Senior Penetration Testing Analyst
Sophos
• Conduct application security assessments (web, mobile, API, etc.) using off-the-shelf or internally developed exploitation tools to execute manual testing for advanced attacks OR network penetration testing assessments (external pen test, internal pen test, etc.) • Produce and deliver vulnerability and exploit information to clients in the form of a professional security assessment report • Conduct client conference calls to include, but not limited to project kick-off calls, notification of high/critical findings during the testing process, and close out calls to review test findings, evidence, process steps to reproduce, and remediation recommendations • Perform proactive research to identify and understand new threats, vulnerabilities, and exploits • Conduct exploitation testing using off-the-shelf or self-developed exploitation tools and document findings for client remediation • Excel as both a self-directed individual contributor and as a member of a larger team • Perform other essential duties as assigned. • Technically help and influence junior teammates to grow together. • Lead our security services as a service owner
Job Requirements
- Minimum of 5 years of experience with web application or penetration testing
- Minimum of 5 years of experience with at least one of the following: Nmap, Metasploit, Kali Linux, Burp Suite
- Native-level Japanese language skills (At minimum, business-level Japanese language skills are required)
- Offensive certifications such as GPEN, GWAPT, OSCP, OSEP, OSWE, OSWP etc.
- Understanding of TCP/IP networking at a technical level
- Bachelor of Science degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field; or equivalent professional experience
- Experience with various application attack vectors, security test processes and strong knowledge of common vulnerabilities (i.e. OWASP Top 10)
- Experience with penetration testing skills against Windows Active Directory or various cloud services such as AWS/Azure/GCP
- Working knowledge of SQL and high-level languages
- Business-level English language skills
- Good technical communication skills, both written and verbal; good analytical and problem-solving skills
- Ability and relevant experience in influencing teammates technically, to help them to succeed in their assigned projects.
Benefits
- Sophos operates a remote-first working model, making remote work the primary option for most employees.
- Employee-led diversity and inclusion networks that build community and provide education and advocacy
- Annual charity and fundraising initiatives and volunteer days for employees to support local communities
- Global employee sustainability initiatives to reduce our environmental footprint
- Global fitness and trivia competitions to keep our bodies and minds sharp
- Global wellbeing days for employees to relax and recharge
- Monthly wellbeing webinars and training to support employee health and wellbeing
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security Program Manager – Governance, Risk, Compliance
UpstartOur mission is to enable effortless credit based on true risk.
• Enable teams to move faster and more securely by acting as a trusted GRC partner, translating audit, risk, and compliance requirements into practical guidance. • Ensure audit readiness and successful outcomes by coordinating core assurance activities, including SOX IT and SOC 2, across engineering, IT, and business teams. • Protect customer and partner trust by managing security due diligence requests from prospective and existing business partners, delivering clear and timely responses. • Strengthen security governance by owning policy management, including drafting, maintaining, reviewing, and driving awareness of information security policies and standards. • Reduce third-party risk by supporting and executing the information security third-party risk management program, including vendor assessments, risk tracking, and remediation follow-up. • Improve the efficiency and consistency of GRC operations through process improvement and thoughtful use of automation and tooling.
• Manage, develop, and retain a team of up to 10 offensive security engineers — setting clear expectations, removing blockers, and building the culture that keeps top 1% talent engaged and growing. • Maintain a maniacal focus on client satisfaction throughout every engagement, ensuring technical precision and a consistently high standard of execution across red team, application security, and cloud security. • Run the team against clearly defined objectives and key results — owning utilization, gross margin, NPS, and career development outcomes quarter over quarter. • Partner with product and engineering leadership to systematically feed real-world offensive findings into the Guard platform, turning field expertise into platform capability. • Identify opportunities to improve engagement methodologies, standardize delivery, and scale throughput without sacrificing depth or quality of findings. • Actively identify and implement AI tools and automation within your team's workflows — reducing manual overhead and increasing delivery capacity without increasing headcount. • Assist sales in managing existing client relationships and winning new logos, showing up as a credible technical leader in front of CISOs and security leadership.
Staff Software Engineer – Application Security
3P&T Security RecruitingEver feel like you don't have the TIME to hire a new employee?
• Work with teams to discover and implement new detection capabilities and logging sources • Be a thought leader in building the security road-map • Be a security subject matter expert and respond to internal security engineering questions/requests • Operate external bug bounty programs to source vulnerability information • Architect, design and implement defensive systems that enhance security • Carefully balance security risk and product advancement • Respond to security and privacy incidents, write incident reports, and participate in post-postmortems • Perform penetration testing on internal and external applications • Integrate customer security requirements into product and system design
• Lead the implementation and optimization of cloud security solutions across complex client environments. • Serve as a technical mentor and escalation point for junior and mid-level engineers. • Collaborate with architects and stakeholders to design scalable, secure, and high-performance cloud architectures. • Design and implement security controls across Azure services including Azure Policy, Microsoft Defender for Cloud, Sentinel, Purview, and DLP/AIP. • Collaborate with infrastructure and application teams to ensure secure deployment of Azure Compute, Networking, and Storage resources. • Monitor and respond to security incidents using Log Analytics and SIEM tools. • Support identity and access management initiatives, including IAM, PIM, and Access Packages. • Develop and maintain security documentation, standards, and best practices. • Contribute to automation efforts using PowerShell, Python, or Bash to streamline security operations. • Participate in security assessments, audits, and compliance initiatives. • Provide guidance on secure architecture and design patterns in Azure. • Stay current with emerging threats, vulnerabilities, and regulatory requirements.



