Ready to strengthen your security posture?
Ethical Hacker
Location
Texas
Posted
13 days ago
Salary
0
Seniority
Senior
Job Description
Ethical Hacker
Packetlabs
• Your primary role is to perform penetration testing of web applications, mobile applications, thick clients, and APIs. • Source code review and whitebox penetration testing to prove the impact of application flaws. • Reverse engineering of mobile and thick client applications. • You sometimes chain application flaws to other areas, such as cloud and on-prem AD infrastructure. • Opportunities for lateral movement into the infrastructure teams are limited and given at the manager's discretion. • Develop detailed reports on findings and remediations for impactful findings. • You will learn to debrief these findings at both a technical and executive level. • Perform SAST and DAST on enterprise, SaaS, and custom in-house applications. • Experience in using scanners and knowledge of validation and elimination of false positives. • A strong understanding of OWASP in Web, API, Mobile, and AI/LLM is necessary, but you will be asked to go beyond.
Job Requirements
- Solid working knowledge of programming languages, including C, C#, Python, Objective-C, Java, JavaScript, SQL, and frameworks like AngularJS.
- Familiarity with web services and data exchange formats such as XML, JSON, SOAP, REST, and AJAX.
- Understanding of AI/LLM weaknesses and flaws in applications.
- Extensive experience/expertise in using an attack proxy (e.g. Burp Suite)
- Preferred if you have 3 - 5 years of experience working in penetration testing and consulting
- A graduate of a post-secondary college or university degree program.
- Has at least two years of experience dealing with information security-related tasks.
- Has professional qualifications (one or more): OSCP, OSWE, BSCP. OSCP or Burp is mandatory for our organization.
Benefits
- Amazing team and working environment
- Competitive compensation and pay for performance
- Employee growth and development
- Fully remote (in Texas)
- At-Will Employment
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
IT Cloud Engineer Security III
Excellus BlueCross BlueShieldUPSTARS – продуктова IT-компанія, з якою злітають і люди, і бренди. Наш основний фокус – технологічні рішення та B2B-послуги для міжнародних клієнтів.
Role Description The IT Cloud Engineer - Security provides the vision, strategy, functionality, and technology solutions for creating and maintaining security systems and solutions for both public and private cloud infrastructure-based solutions. This position collaborates with the Information Technology teams to lead the organization toward the deployment of technologies which focus on the trust, risk, and security management of the company environment. - Enforces and integrates security solutions, tools, and appropriate controls to align to security policies, standards, and procedures. - Stays current with leading security technologies, standards, and best practices as well as cyber threat landscape and evolving mitigation approaches and techniques. - Acts as a high-level escalation tier for operational support in assigned technical areas. - Conducts proof-of-concept testing in a lab environment. - Creates, updates, and maintains supporting documentation for technology standards. - Designs and deploys security solutions to support and ensure alignment with business requirements. - Works with technology vendors and technical subject matter experts (SME) to produce corporate standards with regards to assigned technology areas. - Collaborates and/or leads engineering solutions, integrating multiple systems and/or technologies. - Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies’ mission and values. - Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures. - Regular and reliable attendance is expected and required. - Performs other functions as assigned by management. Qualifications - Level I: Four (4) years of related experience. - Associates degree in Computer Science, Information Technology, or related field. In lieu of degree, three (3) years of related work experience required. Bachelor’s degree preferred. - Intermediate knowledge of security, compliance, and audit policies/procedures. - Basic experience with research, design, and implementation in assigned technologies. - Basic infrastructure operations and infrastructure project delivery experience essential. - Basic scripting and automation experience. - Advanced communication skills. - Intermediate understanding of cloud computing infrastructure and concepts. - Intermediate knowledge of securing cloud and/or on-premises systems. - Intermediate ability to engineer and integrate new security designs. - Demonstrates intermediate knowledge of a minimum of two (2) concepts and/or tools listed below: - Encryption, PKI, Network and application security, and related firewalls (Palo Alto Networks, Imperva, Azure, AWS, etc.) - Identity management (AD, Entra ID, conditional access, MFA, SSO, etc.) - Virus detection and endpoint security (Defender preferred) - Vulnerability scanner and pen testing tools (e.g., Rapid 7, Nessus, Nexpose, Metasploit, Appscan, Burp suite, Ida Pro etc.) - IDS/IPS and related tools - Comprehensive Cloud security platform (Palo Alto Prisma) - Security logging and monitoring (SIEM e.g., ArcSight, Splunk, SolarWinds LEM, Azure Sentinel, AWS Guard Duty, etc.) - Common web application security vulnerabilities (e.g., OWASP) - Application security - Security architecture principles/concepts (i.e., Zero Trust) Requirements - Level II (in addition to Level I responsibilities): - Acts as a primary engineer for assigned technology areas maintaining highly performant and optimized infrastructure environment. - Researches technologies and performs analysis that significantly contributes to budget and expenditures for assigned technology areas. - Collaborates and participates in the development and execution of enterprise strategy in the assigned technology area. - Assists in the RFI/RFP process. - Level III (in addition to Level II responsibilities): - Research and recommend solution designs. - Establishes business justifications for purchases made within assigned technology areas. - Significant contributor to automation workflows and focuses on automation for job-related tasks. - Performs system analysis and capacity planning of security assets. - Assists with mentoring of Level I and II Engineers. - Level IV (in addition to Level III responsibilities): - Acts as trusted advisor to the management team. - Emphasizes technology cost optimization when designing new solutions. - Leads business critical projects efforts for IT infrastructure. - Leads internal strategic efforts, collaborates, and mentors peers. Benefits - Participation in group health and/or dental insurance. - Retirement plan. - Wellness program. - Paid time away from work. - Paid holidays. Compensation Range(s) - Level I - Min 79,068 Max 142,322 - Level II - Min 87,766 Max 157,978 - Level III - Min 98,297 Max 176,935 - Level IV - Min 110,093 Max 198,168 Physical Requirements - Ability to travel across the Health Plan service region for meetings and/or trainings as needed. - Ability to work in a home office for continuous periods of time for business continuity. - Ability to provide on-call rotation support.
Senior Product Security Engineer
Vertex Inc.Vertex is a global biotechnology company that invests in scientific innovation.
Role Description This role requires practical, hands-on AI fluency. The ideal candidate is comfortable operating directly within the product development lifecycle—understanding how modern AI systems and agents behave, improve over time, and fail—and applying that understanding to product security decisions, acceptance criteria, and release readiness while owning and evolving broader product security strategy, governance, and risk management practices across the organization. - Own and evolve major components of the Product Security strategy, translating product and business risk into actionable, measurable security programs with clear success metrics. - Lead Secure-by-Design initiatives across product teams, embedding security requirements early in product and feature design, and defining secure design patterns, reference architectures, and guardrails that scale. - Lead security architecture reviews, secure code reviews, threat modeling, and application penetration testing, with a focus on systemic risk reduction across a broad range of products. - Establish and own security best practices for AI-enabled product features, model integration, and AI service architectures, including data handling, model access, and inference workflows. - Lead AI-specific threat modeling addressing misuse, data leakage, supply-chain exposure, and abuse scenarios; define security controls and governance requirements specific to AI features and services. - Evaluate the security implications of new AI technologies, tools, and models prior to adoption; embed responsible AI principles—traceability, privacy, bias awareness, transparency, and auditability—into product security decisions. - Drive consistency in how product and AI risks are assessed, documented, tracked, and accepted across the organization. - Serve as advisor to product and engineering on security risk, architectural trade-offs, and risk acceptance decisions. - Mentor and provide technical leadership to other Product Security engineers and serve as an escalation point for complex security decisions. Qualifications - 5+ years of experience in the security domain, including applying security controls to cloud-based technologies and implementing Product Security frameworks such as OWASP, CIS Benchmarks, and Cloud Security Alliance (CSA). - Proven track record of establishing security controls and governance requirements for AI-enabled features, including data handling, model access, and inference workflows. - Hands-on experience with AI product development security, including partnering with engineering and subject matter experts on model evaluation, tuning, and training. - Ability to define evaluation criteria for AI systems and interpret results to inform security requirements and release readiness decisions. - Experience with cloud governance principles and Product Security tooling, including SAST and DAST. - Demonstrated ability to lead threat modeling, secure code reviews, and application penetration testing for complex, cross-cutting security issues. - Demonstrated expertise in defining and scaling secure design patterns, reference architectures, and security guardrails across multiple product teams. - Technical acumen to experiment directly with AI tools and prototypes in support of faster product security validation. Requirements - Bachelor's degree in computer science or a related field; equivalent combination of education, training, and relevant professional experience accepted in lieu of a formal degree. - Experience with DevSecOps practices, zero trust design principles, and cloud incident response. - Experience contributing to the automation of security analysis and testing activities. - Track record of mentoring and providing technical leadership to security engineering teams. Other Qualifications - Communicate with Clarity - Be clear, concise and actionable. Be relentlessly constructive. Seek and provide meaningful feedback. - Act with Urgency - Adopt an agile mentality - frequent iterations, improved speed, resilience. 80/20 rule – better is the enemy of done. Don’t spend hours when minutes are enough. - Work with Purpose - Exhibit a “We Can” mindset. Results outweigh effort. Everyone understands how their role contributes. Set aside personal objectives for team results. - Drive to Decision - Cut the swirl with defined deadlines and decision points. Be clear on individual accountability and decision authority. Guided by a commitment to and accountability for customer outcomes. - Own the Outcome - Defined milestones, commitments and intended results. Assess your work in context, if you’re unsure, ask. Demonstrate unwavering support for decisions. Pay Transparency Statement Base pay offered to new hires may vary based upon factors including relevant industry and job-related skills and experience, geographic location, and business needs. The range displayed does not encompass the full potential of the role, which allows for further growth and career progression. In addition, as a part of our total compensation package, this role may be eligible for the Vertex Bonus Plan (VOB), a role-specific sales commission/bonus, and/or equity grants.
Information Security Engineer I
Conduent Business Services, LLCConduent delivers mission-critical services and solutions on behalf of Fortune 100 companies and over 500 governments, creating exceptional outcomes for our clients and the millions of people who count on them. We foster a truly global culture that supports well-being, values every contribution, and empowers our people to grow both personally and professionally.
Role Description The Information Security Engineer I is a professional member of the CISO Identity & Access Management team supporting implementation, administration, and monitoring of identity and access management controls across the organization. This role focuses on user access provisioning, identity lifecycle processes, and assisting with IAM tools and security controls under the guidance of senior engineers. This is an entry-level position designed for individuals looking to build a career in cybersecurity and identity security. Responsibilities - Execute user access provisioning and deprovisioning requests (joiner, mover, leaver) - Validate access requests for completeness and proper authorization - Assist in maintaining role-based access models (RBAC) - Support management of Active Directory, Entra ID (Azure AD), or similar directories - Support day-to-day operations of IAM platforms (e.g., Okta, SailPoint, Saviynt, Entra ID) - Assist with onboarding applications into IAM systems - Help troubleshoot user access issues and authentication failures - Maintain documentation of IAM processes and procedures - Help enforce basic least privilege and access policies - Work with IT, HR, and business units to fulfill access requests - Communicate clearly with end users regarding access issues - Participate in team meetings and knowledge-sharing activities - Participate in compliance audits and support IAM audits and reporting - Identify risks and recommend solutions to ensure compliance with IAM standards - Work with the IAM team to resolve identity and access management problems - Maintain up-to-date knowledge of identity and access management best practices - Document IAM processes and procedures Qualifications - Bachelor’s degree or better in information technology, information security, computer science or a related field - (0 to 2) Years of experience in IT, Security, or Identity-related role - Basic understanding of IAM concepts and best practices - Basic understanding of information security and/or information technology techniques and practices - Ability to work remotely with limited direct supervision - Strong interest in cybersecurity and identity governance Requirements - Pay Transparency Laws in some locations require disclosure of compensation and/or benefits-related information. For this position, actual salaries will vary and may be above or below the range based on various factors including but not limited to location, experience, and performance. - In addition to base pay, this position, based on business need, may be eligible for a bonus or incentive. Benefits - Health insurance coverage - Voluntary dental and vision programs - Life and disability insurance - Retirement savings plan - Paid holidays - Paid time off (PTO) or vacation and/or sick time
Information System Security Officer – ISSO
General DynamicsA business unit of General Dynamics, General Dynamics Information Technology (GDIT) supports some of the United States' most complex government, defense, and intelligence projects.
• Ensure the continuous monitoring of security and privacy controls • Work closely with Information System Owner, Information System Security Manager, system administrators, and other IT and privacy professionals • Manage the security aspects of an information system • Conduct threat analysis, vulnerability assessments, and compliance monitoring • Prepare, review, and update authorization packages and associated artifacts • Coordinate annual incident management and COOP/DR tabletop exercises

