Sophos logo
Sophos

Defeat Cyberattacks

Senior Penetration Testing Analyst

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000Since 1985H1B SponsorCompany SiteLinkedIn

Location

Japan

Posted

75 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expJapaneseEnglishAWSAzureCloudGoogle Cloud PlatformLinuxSQLTCP/IP

Job Description

Senior Penetration Testing Analyst

Sophos

• Conduct application security assessments (web, mobile, API, etc.) using off-the-shelf or internally developed exploitation tools to execute manual testing for advanced attacks OR network penetration testing assessments (external pen test, internal pen test, etc.) • Produce and deliver vulnerability and exploit information to clients in the form of a professional security assessment report • Conduct client conference calls to include, but not limited to project kick-off calls, notification of high/critical findings during the testing process, and close out calls to review test findings, evidence, process steps to reproduce, and remediation recommendations • Perform proactive research to identify and understand new threats, vulnerabilities, and exploits • Conduct exploitation testing using off-the-shelf or self-developed exploitation tools and document findings for client remediation • Excel as both a self-directed individual contributor and as a member of a larger team • Perform other essential duties as assigned. • Technically help and influence junior teammates to grow together. • Lead our security services as a service owner

Job Requirements

  • Minimum of 5 years of experience with web application or penetration testing
  • Minimum of 5 years of experience with at least one of the following: Nmap, Metasploit, Kali Linux, Burp Suite
  • Native-level Japanese language skills (At minimum, business-level Japanese language skills are required)
  • Offensive certifications such as GPEN, GWAPT, OSCP, OSEP, OSWE, OSWP etc.
  • Understanding of TCP/IP networking at a technical level
  • Bachelor of Science degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field; or equivalent professional experience
  • Experience with various application attack vectors, security test processes and strong knowledge of common vulnerabilities (i.e. OWASP Top 10)
  • Experience with penetration testing skills against Windows Active Directory or various cloud services such as AWS/Azure/GCP
  • Working knowledge of SQL and high-level languages
  • Business-level English language skills
  • Good technical communication skills, both written and verbal; good analytical and problem-solving skills
  • Ability and relevant experience in influencing teammates technically, to help them to succeed in their assigned projects.

Benefits

  • Sophos operates a remote-first working model, making remote work the primary option for most employees.
  • Employee-led diversity and inclusion networks that build community and provide education and advocacy
  • Annual charity and fundraising initiatives and volunteer days for employees to support local communities
  • Global employee sustainability initiatives to reduce our environmental footprint
  • Global fitness and trivia competitions to keep our bodies and minds sharp
  • Global wellbeing days for employees to relax and recharge
  • Monthly wellbeing webinars and training to support employee health and wellbeing

Related Categories

Related Job Pages

More Security Engineer Jobs

Upstart logo

Information Security Program Manager – Governance, Risk, Compliance

Upstart

Our mission is to enable effortless credit based on true risk.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Enable teams to move faster and more securely by acting as a trusted GRC partner, translating audit, risk, and compliance requirements into practical guidance. • Ensure audit readiness and successful outcomes by coordinating core assurance activities, including SOX IT and SOC 2, across engineering, IT, and business teams. • Protect customer and partner trust by managing security due diligence requests from prospective and existing business partners, delivering clear and timely responses. • Strengthen security governance by owning policy management, including drafting, maintaining, reviewing, and driving awareness of information security policies and standards. • Reduce third-party risk by supporting and executing the information security third-party risk management program, including vendor assessments, risk tracking, and remediation follow-up. • Improve the efficiency and consistency of GRC operations through process improvement and thoughtful use of automation and tooling.

United States
$115.8K - $160.1K / year
Job Closed

• Manage, develop, and retain a team of up to 10 offensive security engineers — setting clear expectations, removing blockers, and building the culture that keeps top 1% talent engaged and growing. • Maintain a maniacal focus on client satisfaction throughout every engagement, ensuring technical precision and a consistently high standard of execution across red team, application security, and cloud security. • Run the team against clearly defined objectives and key results — owning utilization, gross margin, NPS, and career development outcomes quarter over quarter. • Partner with product and engineering leadership to systematically feed real-world offensive findings into the Guard platform, turning field expertise into platform capability. • Identify opportunities to improve engagement methodologies, standardize delivery, and scale throughput without sacrificing depth or quality of findings. • Actively identify and implement AI tools and automation within your team's workflows — reducing manual overhead and increasing delivery capacity without increasing headcount. • Assist sales in managing existing client relationships and winning new logos, showing up as a credible technical leader in front of CISOs and security leadership.

United States
3P&T Security Recruiting logo

Staff Software Engineer – Application Security

3P&T Security Recruiting

Ever feel like you don't have the TIME to hire a new employee?

Full TimeRemoteTeam 1-10H1B No Sponsor

• Work with teams to discover and implement new detection capabilities and logging sources • Be a thought leader in building the security road-map • Be a security subject matter expert and respond to internal security engineering questions/requests • Operate external bug bounty programs to source vulnerability information • Architect, design and implement defensive systems that enhance security • Carefully balance security risk and product advancement • Respond to security and privacy incidents, write incident reports, and participate in post-postmortems • Perform penetration testing on internal and external applications • Integrate customer security requirements into product and system design

Washington
3Cloud logo

Senior Cloud Security Engineer – Azure

3Cloud

Delivering the ultimate Microsoft Azure experience.

Full TimeRemoteTeam 501-1,000H1B No Sponsor

• Lead the implementation and optimization of cloud security solutions across complex client environments. • Serve as a technical mentor and escalation point for junior and mid-level engineers. • Collaborate with architects and stakeholders to design scalable, secure, and high-performance cloud architectures. • Design and implement security controls across Azure services including Azure Policy, Microsoft Defender for Cloud, Sentinel, Purview, and DLP/AIP. • Collaborate with infrastructure and application teams to ensure secure deployment of Azure Compute, Networking, and Storage resources. • Monitor and respond to security incidents using Log Analytics and SIEM tools. • Support identity and access management initiatives, including IAM, PIM, and Access Packages. • Develop and maintain security documentation, standards, and best practices. • Contribute to automation efforts using PowerShell, Python, or Bash to streamline security operations. • Participate in security assessments, audits, and compliance initiatives. • Provide guidance on secure architecture and design patterns in Azure. • Stay current with emerging threats, vulnerabilities, and regulatory requirements.

Philippines