Packetlabs logo
Packetlabs

Ready to strengthen your security posture?

Ethical Hacker

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2011H1B No SponsorCompany SiteLinkedIn

Location

Texas

Posted

66 days ago

Salary

0

Seniority

Senior

Postgraduate Degree3 yrs expExperience acceptedEnglishAngularCloudJavaJavaScriptObjective-CPythonSOAPSQL

Job Description

Ethical Hacker

Packetlabs

• Your primary role is to perform penetration testing of web applications, mobile applications, thick clients, and APIs. • Source code review and whitebox penetration testing to prove the impact of application flaws. • Reverse engineering of mobile and thick client applications. • You sometimes chain application flaws to other areas, such as cloud and on-prem AD infrastructure. • Opportunities for lateral movement into the infrastructure teams are limited and given at the manager's discretion. • Develop detailed reports on findings and remediations for impactful findings. • You will learn to debrief these findings at both a technical and executive level. • Perform SAST and DAST on enterprise, SaaS, and custom in-house applications. • Experience in using scanners and knowledge of validation and elimination of false positives. • A strong understanding of OWASP in Web, API, Mobile, and AI/LLM is necessary, but you will be asked to go beyond.

Job Requirements

  • Solid working knowledge of programming languages, including C, C#, Python, Objective-C, Java, JavaScript, SQL, and frameworks like AngularJS.
  • Familiarity with web services and data exchange formats such as XML, JSON, SOAP, REST, and AJAX.
  • Understanding of AI/LLM weaknesses and flaws in applications.
  • Extensive experience/expertise in using an attack proxy (e.g. Burp Suite)
  • Preferred if you have 3 - 5 years of experience working in penetration testing and consulting
  • A graduate of a post-secondary college or university degree program.
  • Has at least two years of experience dealing with information security-related tasks.
  • Has professional qualifications (one or more): OSCP, OSWE, BSCP. OSCP or Burp is mandatory for our organization.

Benefits

  • Amazing team and working environment
  • Competitive compensation and pay for performance
  • Employee growth and development
  • Fully remote (in Texas)
  • At-Will Employment

Related Categories

Related Job Pages

More Security Engineer Jobs

Application Security Architect

WEXWEXUS

WEX simplifies the business of running a business through smarter workflows and financial intelligence. Our North America Mobility and OTR businesses power the fleets that keep commerce moving — from small owner-operators to large fleet enterprises. Pay Range $198,000.00 - $223,700.00

Role Description Wex, Inc. is looking for an Application Security Architect with broad software development and application security experience. This individual would be responsible for designing, guiding, and assessing security solutions in software projects to ensure that security is built in from the beginning. With the assistance of tools including SAST, DAST and SCA, perform assessments of software projects to identify security issues and guide teams to effective remediations. We’re the Global Product Security Team at WEX, responsible for enabling a modern and effective Secure Software Development Lifecycle throughout WEX. We partner closely with internal teams and customers to assure WEX operates in a secure and compliant manner. Our team holds itself to a high standard and we collaborate closely with one another to ensure strong, reliable and effective relationships. We own our results and we take pride of ownership in everything we do. Qualifications - A highly motivated security architect who loves working on small, high performing teams that interface with the entire enterprise. - A collaborative, solid communicator who works well with your team and stakeholders to drive projects from inception to completion. - Someone who cares deeply for team results but is able to work independently to deliver high quality solutions for projects and operational tasks. - Comfortable balancing the need to move fast with the realities of working in a highly regulated organization. - Passionate about security, but pragmatic about delivering business value. - Customer focused - whether it’s internal teams that we’re supporting or the WEX partner, you prioritize ensuring they have a great experience with WEX and our team. - A skilled worker that has the motivation, expertise, and work ethic to operate independently across global time zones, and who is able to complete tasks and deliverables with minimal oversight. - A leader who builds consensus and drives change through buy-in and education rather than mandates. - Able to mentor other engineers & architects on your team and other teams both technically and professionally. - Champion of a shift-left and DevSecOps approach to security, but tenacious enough to build such a program from the ground up. - A lifelong learner that is excited by new technologies and challenges. Requirements - Subject Matter Expert in software development and software security, particularly with web applications, APIs, mobile apps and enterprise applications delivered in a SaaS model. - Perform manual and automated secure code reviews, assisted with commercial static and dynamic application security scanning tools (SAST, DAST, SCA, etc). - Do web application and mobile app penetration testing. - Deliver actionable security guidance to project teams. - Analyze security assessments and effectively communicate requirements to appropriate software development, network and configuration management teams. - Actively participate in Security Development Lifecycle efforts such as performing secure architecture reviews, secure code reviews, threat models and penetration testing through the software development lifecycle. - Keep abreast of security industry best practices and OWASP recommendations utilizing knowledge to contribute to remediation efforts across the platform, as well as security policies and procedures. - Identify and partner with security champions in the development organization to scale security expertise and awareness. - Write comprehensive reports including assessment-based findings, outcomes and recommendations for security enhancement. - Deep experience working with compliance and regulatory frameworks such as PCI-DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc. - 3-5+ years of progressive experience in software development. C#, Java, Go or Python preferred. - 3+ years experience with software security or information security. - 2+ years experience with application and container security tools such as SAST, DAST, SCA, IaC scanning and container image scanning, including integrating them to build and ticketing tools. - Very familiar with common application security issues, i.e., OWASP Top10, and appropriate mitigation strategies. - Able to troubleshoot security issues within a complex on-prem and multi-cloud environment. - A degree in Business, Computer Science or equivalent combination of education and relevant experience. - Experience working closely with many teams across departmental and business unit boundaries. - Can commit and deliver on very specific project/delivery timelines with minimal supervision. - Excellent communication skills, both written and verbal. Benefits - Health, dental and vision insurances. - Retirement savings plan. - Paid time off. - Health savings account. - Flexible spending accounts. - Life insurance. - Disability insurance. - Tuition reimbursement. - Comprehensive and market competitive benefits designed to support your personal and professional well-being. Pay Range $109,300.00 - $133,000.00

United States
$109.3K - $133K / year
Job Closed
Excellus BlueCross BlueShield logo

IT Cloud Engineer Security III

Excellus BlueCross BlueShield

UPSTARS – продуктова IT-компанія, з якою злітають і люди, і бренди. Наш основний фокус – технологічні рішення та B2B-послуги для міжнародних клієнтів.

Full TimeRemoteTeam 2-10H1B No Sponsor

Role Description The IT Cloud Engineer - Security provides the vision, strategy, functionality, and technology solutions for creating and maintaining security systems and solutions for both public and private cloud infrastructure-based solutions. This position collaborates with the Information Technology teams to lead the organization toward the deployment of technologies which focus on the trust, risk, and security management of the company environment. - Enforces and integrates security solutions, tools, and appropriate controls to align to security policies, standards, and procedures. - Stays current with leading security technologies, standards, and best practices as well as cyber threat landscape and evolving mitigation approaches and techniques. - Acts as a high-level escalation tier for operational support in assigned technical areas. - Conducts proof-of-concept testing in a lab environment. - Creates, updates, and maintains supporting documentation for technology standards. - Designs and deploys security solutions to support and ensure alignment with business requirements. - Works with technology vendors and technical subject matter expert (SME) to produce corporate standards with regards to assigned technology areas. - Collaborates and/or leads engineering solutions, integrating multiple systems and/or technologies. - Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies’ mission and values, adhering to the Corporate Code of Conduct, and leading to the Lifetime Way values and beliefs. - Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures. - Regular and reliable attendance is expected and required. - Performs other functions as assigned by management. Level II (In addition to Level I responsibilities): - Acts as a primary engineer for assigned technology areas maintaining highly performant and optimized infrastructure environment. - Researches technologies and performs analysis that significantly contributes to budget and expenditures for assigned technology areas. - Collaborates and participates in the development and execution enterprise strategy in the assigned technology area. - Assists in the RFI/RFP process. Level III (In addition to Level II responsibilities): - Research and recommended solution designs. Establishes business justifications for purchases made within assigned technology areas. - Significant contributor to automation workflows and focuses on automation for job-related tasks. - Performs system analysis and capacity planning of security assets. - Assists with mentoring of Level I and II Engineers. Level IV (In addition to level III responsibilities): - Acts as trusted advisor to the management team. - Emphasizes technology cost optimization when designing new solutions. - Leads business critical projects efforts for IT infrastructure. - Leads internal strategic efforts, collaborates, and mentors peers. Qualifications - Level I: Four (4) years of related experience. - Associates degree in Computer Science, Information Technology, or related field. In lieu of degree, three (3) years of related work experience required. Bachelor’s degree preferred. - Intermediate knowledge of security, compliance, and audit policies/procedures. - Basic experience with research, design, and implementation in assigned technologies. - Basic infrastructure operations and infrastructure project delivery experience essential. - Basic scripting and automation experience. - Advanced communication skills. - Intermediate understanding of cloud computing infrastructure and concepts. - Intermediate knowledge of securing cloud and/or on-prem. - Intermediate ability to engineer and integrate new security designs with an emphasis on solutions that align with overall security strategy. - Demonstrates intermediate knowledge of a minimum of two (2) concepts and/or tools listed below: Encryption, PKI, Network and application security, and related firewalls, Identity management, Virus detection and end point security, Vulnerability scanner and pen testing tools, IDS/IPS and related tools, Comprehensive Cloud security platform, Security logging and monitoring, Common web application security vulnerabilities, Application security, Security architecture principals/concepts. - Level II: Intermediate knowledge of security, compliance, and audit policies/procedures. - Intermediate knowledge of a minimum of three (3) concepts and/or tools listed above. - Intermediate Security operations and infrastructure project delivery experience. - Demonstrates intermediate technical documentation ability. - Intermediate experience with IT computing resource management and optimization. - Displays advanced business maturity and demonstrated confidentiality. - Intermediate knowledge of Disaster Recovery. - Level III: Advanced knowledge of a minimum of four (4) concepts and/or tools listed above. - Strategic vision in alignment with business objectives. - Intermediate scripting and automation experience preferred. - Level IV: Advanced knowledge of a minimum of five (5) concepts and/or tools listed above. - Demonstrated advanced competency in team leadership/technical leadership, facilitation, and project leadership. - Advanced understanding of Disaster Recovery procedures related to IT infrastructure. - Advanced knowledge of security, compliance, and audit policies/procedures. - Advanced scripting and automation experience. Requirements - Ability to travel across the Health Plan service region for meetings and/or trainings as needed. - Ability to work in a home office for continuous periods of time for business continuity. - Ability to provide on-call rotation support. Compensation Range(s) - Level I - Min 79,068 Max 142,322 - Level II - Min 87,766 Max 157,978 - Level III - Min 98,297 Max 176,935 - Level IV - Min 110,093 Max 198,168 The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position’s minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Please note: There may be opportunity for remote work within all jobs posted by the Excellus Talent Acquisition team. This decision is made on a case-by-case basis. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

United States
$98.3K - $176.9K / year
Job Closed
Excellus BlueCross BlueShield logo

IT Cloud Engineer Security III

Excellus BlueCross BlueShield

UPSTARS – продуктова IT-компанія, з якою злітають і люди, і бренди. Наш основний фокус – технологічні рішення та B2B-послуги для міжнародних клієнтів.

Full TimeRemoteTeam 2-10H1B No Sponsor

Role Description The IT Cloud Engineer - Security provides the vision, strategy, functionality, and technology solutions for creating and maintaining security systems and solutions for both public and private cloud infrastructure-based solutions. This position collaborates with the Information Technology teams to lead the organization toward the deployment of technologies which focus on the trust, risk, and security management of the company environment. - Enforces and integrates security solutions, tools, and appropriate controls to align to security policies, standards, and procedures. - Stays current with leading security technologies, standards, and best practices as well as cyber threat landscape and evolving mitigation approaches and techniques. - Acts as a high-level escalation tier for operational support in assigned technical areas. - Conducts proof-of-concept testing in a lab environment. - Creates, updates, and maintains supporting documentation for technology standards. - Designs and deploys security solutions to support and ensure alignment with business requirements. - Works with technology vendors and technical subject matter experts (SME) to produce corporate standards with regards to assigned technology areas. - Collaborates and/or leads engineering solutions, integrating multiple systems and/or technologies. - Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies’ mission and values. - Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures. - Regular and reliable attendance is expected and required. - Performs other functions as assigned by management. Qualifications - Level I: Four (4) years of related experience. - Associates degree in Computer Science, Information Technology, or related field. In lieu of degree, three (3) years of related work experience required. Bachelor’s degree preferred. - Intermediate knowledge of security, compliance, and audit policies/procedures. - Basic experience with research, design, and implementation in assigned technologies. - Basic infrastructure operations and infrastructure project delivery experience essential. - Basic scripting and automation experience. - Advanced communication skills. - Intermediate understanding of cloud computing infrastructure and concepts. - Intermediate knowledge of securing cloud and/or on-premises systems. - Intermediate ability to engineer and integrate new security designs. - Demonstrates intermediate knowledge of a minimum of two (2) concepts and/or tools listed below: - Encryption, PKI, Network and application security, and related firewalls (Palo Alto Networks, Imperva, Azure, AWS, etc.) - Identity management (AD, Entra ID, conditional access, MFA, SSO, etc.) - Virus detection and endpoint security (Defender preferred) - Vulnerability scanner and pen testing tools (e.g., Rapid 7, Nessus, Nexpose, Metasploit, Appscan, Burp suite, Ida Pro etc.) - IDS/IPS and related tools - Comprehensive Cloud security platform (Palo Alto Prisma) - Security logging and monitoring (SIEM e.g., ArcSight, Splunk, SolarWinds LEM, Azure Sentinel, AWS Guard Duty, etc.) - Common web application security vulnerabilities (e.g., OWASP) - Application security - Security architecture principles/concepts (i.e., Zero Trust) Requirements - Level II (in addition to Level I responsibilities): - Acts as a primary engineer for assigned technology areas maintaining highly performant and optimized infrastructure environment. - Researches technologies and performs analysis that significantly contributes to budget and expenditures for assigned technology areas. - Collaborates and participates in the development and execution of enterprise strategy in the assigned technology area. - Assists in the RFI/RFP process. - Level III (in addition to Level II responsibilities): - Research and recommend solution designs. - Establishes business justifications for purchases made within assigned technology areas. - Significant contributor to automation workflows and focuses on automation for job-related tasks. - Performs system analysis and capacity planning of security assets. - Assists with mentoring of Level I and II Engineers. - Level IV (in addition to Level III responsibilities): - Acts as trusted advisor to the management team. - Emphasizes technology cost optimization when designing new solutions. - Leads business critical projects efforts for IT infrastructure. - Leads internal strategic efforts, collaborates, and mentors peers. Benefits - Participation in group health and/or dental insurance. - Retirement plan. - Wellness program. - Paid time away from work. - Paid holidays. Compensation Range(s) - Level I - Min 79,068 Max 142,322 - Level II - Min 87,766 Max 157,978 - Level III - Min 98,297 Max 176,935 - Level IV - Min 110,093 Max 198,168 Physical Requirements - Ability to travel across the Health Plan service region for meetings and/or trainings as needed. - Ability to work in a home office for continuous periods of time for business continuity. - Ability to provide on-call rotation support.

United States
$98.3K - $176.9K / year
Job Closed
Vertex Inc. logo

Senior Product Security Engineer

Vertex Inc.

Vertex is a global biotechnology company that invests in scientific innovation.

Full TimeRemoteTeam 1,001-5,000

Role Description This role requires practical, hands-on AI fluency. The ideal candidate is comfortable operating directly within the product development lifecycle—understanding how modern AI systems and agents behave, improve over time, and fail—and applying that understanding to product security decisions, acceptance criteria, and release readiness while owning and evolving broader product security strategy, governance, and risk management practices across the organization. - Own and evolve major components of the Product Security strategy, translating product and business risk into actionable, measurable security programs with clear success metrics. - Lead Secure-by-Design initiatives across product teams, embedding security requirements early in product and feature design, and defining secure design patterns, reference architectures, and guardrails that scale. - Lead security architecture reviews, secure code reviews, threat modeling, and application penetration testing, with a focus on systemic risk reduction across a broad range of products. - Establish and own security best practices for AI-enabled product features, model integration, and AI service architectures, including data handling, model access, and inference workflows. - Lead AI-specific threat modeling addressing misuse, data leakage, supply-chain exposure, and abuse scenarios; define security controls and governance requirements specific to AI features and services. - Evaluate the security implications of new AI technologies, tools, and models prior to adoption; embed responsible AI principles—traceability, privacy, bias awareness, transparency, and auditability—into product security decisions. - Drive consistency in how product and AI risks are assessed, documented, tracked, and accepted across the organization. - Serve as advisor to product and engineering on security risk, architectural trade-offs, and risk acceptance decisions. - Mentor and provide technical leadership to other Product Security engineers and serve as an escalation point for complex security decisions. Qualifications - 5+ years of experience in the security domain, including applying security controls to cloud-based technologies and implementing Product Security frameworks such as OWASP, CIS Benchmarks, and Cloud Security Alliance (CSA). - Proven track record of establishing security controls and governance requirements for AI-enabled features, including data handling, model access, and inference workflows. - Hands-on experience with AI product development security, including partnering with engineering and subject matter experts on model evaluation, tuning, and training. - Ability to define evaluation criteria for AI systems and interpret results to inform security requirements and release readiness decisions. - Experience with cloud governance principles and Product Security tooling, including SAST and DAST. - Demonstrated ability to lead threat modeling, secure code reviews, and application penetration testing for complex, cross-cutting security issues. - Demonstrated expertise in defining and scaling secure design patterns, reference architectures, and security guardrails across multiple product teams. - Technical acumen to experiment directly with AI tools and prototypes in support of faster product security validation. Requirements - Bachelor's degree in computer science or a related field; equivalent combination of education, training, and relevant professional experience accepted in lieu of a formal degree. - Experience with DevSecOps practices, zero trust design principles, and cloud incident response. - Experience contributing to the automation of security analysis and testing activities. - Track record of mentoring and providing technical leadership to security engineering teams. Other Qualifications - Communicate with Clarity - Be clear, concise and actionable. Be relentlessly constructive. Seek and provide meaningful feedback. - Act with Urgency - Adopt an agile mentality - frequent iterations, improved speed, resilience. 80/20 rule – better is the enemy of done. Don’t spend hours when minutes are enough. - Work with Purpose - Exhibit a “We Can” mindset. Results outweigh effort. Everyone understands how their role contributes. Set aside personal objectives for team results. - Drive to Decision - Cut the swirl with defined deadlines and decision points. Be clear on individual accountability and decision authority. Guided by a commitment to and accountability for customer outcomes. - Own the Outcome - Defined milestones, commitments and intended results. Assess your work in context, if you’re unsure, ask. Demonstrate unwavering support for decisions. Pay Transparency Statement Base pay offered to new hires may vary based upon factors including relevant industry and job-related skills and experience, geographic location, and business needs. The range displayed does not encompass the full potential of the role, which allows for further growth and career progression. In addition, as a part of our total compensation package, this role may be eligible for the Vertex Bonus Plan (VOB), a role-specific sales commission/bonus, and/or equity grants.

United States
Job Closed