Your future. Secured.
Security Engineer – Penetration Testing
Location
United States
Posted
19 hours ago
Salary
0
Seniority
Senior
Job Description
Security Engineer – Penetration Testing
ISC2
• Plan, execute, and document internal and external penetration tests against ISC2 applications, networks, cloud environments, and infrastructure. • Perform vulnerability assessments and validate findings to distinguish genuine risks from false positives. • Conduct web application, API, mobile, and network vulnerability assessments using industry-standard methodologies (OWASP, PTES, OSSTMM). • Perform social engineering assessments, including phishing simulations and physical security testing as authorized. • Produce clear, actionable written reports detailing findings, risk ratings, evidence, and remediation recommendations tailored to both technical and executive audiences. • Support red team exercises and adversary simulation activities to test detection and response capabilities. • Own remediation follow-through: translate pen test findings into security engineering work items, validate fixes, and track resolution to closure in Jira Service Management. • Design and implement security controls across ISC2’s cloud and on-premises environments, including hardening configurations for Azure, Okta, SentinelOne, CheckPoint, and F5 XD. • Maintain awareness of emerging vulnerabilities, exploits, and threat actor TTPs; operationalize threat intelligence into actionable hardening and detection improvements.
Job Requirements
- Proficiency with penetration testing tools including Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike, and similar offensive frameworks.
- Strong understanding of web application vulnerabilities (OWASP Top 10), network protocols, Active Directory attack paths, and cloud security (Azure, AWS, GCP).
- Effective written and verbal communication with cross-functional teams is essential.
- Scripting and automation proficiency in Python, Bash, or PowerShell; ability to write or modify exploit code as well as defensive tooling.
- Familiarity with MITRE ATT&CK, CVSS, CVE, NIST SP 800-115, and the CIS Benchmarks for secure configuration baselines.
- Posess AI literacy and ability to test Ai workloads and infrastructures.
- Relevant certifications strongly preferred: OSCP, GPEN or GWAPT, plus one engineering/architecture credential (CISSP, CSSLP, or equivalent).
- ISC2 membership or certifications (CISSP, CC) are a plus and demonstrate alignment with ISC2’s mission.
Benefits
- Health insurance
- Paid time off
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More QA Engineer Jobs
Senior Technical Quality Engineer
Sungrow USA CorporationSungrow Power Supply Co., Ltd. (Stock code: 300274) is a globally recognized renewable energy company, specializing in R&D, manufacturing, and services for solar, wind, energy storage, hydrogen, and electric vehicle solutions. Established in 1997, Sungrow is known for its innovative photovoltaic inverters, wind converters, EV chargers, energy storage systems, and hydrogen production technologies. Its products are sold in over 180 countries, with a cumulative installed capacity exceeding 740 GW by the end of 2024. Sungrow has contributed to national standards and holds numerous core technologies. With multiple industry awards and advanced R&D centers, it ranks among the global leaders in clean energy. Guided by its mission “Clean power for all,” Sungrow continues to drive innovation and global sustainability.
Role Description The Senior Technical Quality Engineer leads quality function within Service Engineering, driving quality strategy, quality improvement, and engineering change governance for Sungrow’s PV product portfolio. This role is responsible for establishing a closed-loop quality management system from quality data to headquarters, ensuring structured data analysis, timely escalation of critical issues, and execution of corrective and preventive actions. The position serves as a key cross-functional leader, collaborating with CoE, R&D in HQ, Field Service, and Supply Chain teams to enhance product performance, reduce warranty exposure, and improve customer satisfaction. Essential Duties and Responsibilities - Strategic Quality Lead - Lead the development of global quality monitoring frameworks using field data, warranty records, and shipment data. - Identify systemic quality risks and proactively drive mitigation and escalation. - Advanced Data Analytics & Quality Insights - Lead data-driven quality analysis including: - Warranty ticket trends - Failure mode identification - Component risk assessment - Develop predictive insights to identify emerging quality risks and support proactive decision-making. - Deliver executive-level reports and recommendations based on structured data analysis. - Engineering Change & Rework Governance - Own the end-to-end engineering change (rework) lifecycle, from issue identification to global deployment. - Establish governance processes for change prioritization, validation, and release readiness. - Ensure consistent implementation of rework programs across regions and functions. - Review and approve engineering change procedures and release documentation. - Cross-Functional Leadership & Stakeholder Management - Act as the primary driver as technical quality interface across: - Headquarters R&D teams - Field Service and regional operations - Quality CoE and supply chain organizations - Drive root cause analysis (RCA) closure and corrective action implementation. - Lead cross-functional task forces to resolve high-impact or escalated quality issues. - Field Quality Operations & Escalation Management - Own and lead resolution of high-severity field issues and customer escalations. - Establish and deploy quality alert frameworks with contingency plans. - Support field teams with complex troubleshooting and validation activities. - Participate in critical field quality assessments and site inspections as required. - Capability Building & Continuous Improvement - Drive improvements in quality systems, tools, and processes (including data platforms such as Airtable). - Develop standardized processes for: - Issue tracking - Quality reporting - Engineering change documentation - Mentor and develop junior engineers, strengthening technical and analytical capabilities. - Governance, Compliance & Reporting - Own executive-level reporting on: - Field performance trends - Major quality incidents - Corrective action effectiveness - Ensure compliance with internal quality standards and documentation requirements. - Maintain comprehensive records of quality investigations, engineering changes, and field cases. Qualifications - 3–5+ years of experience in solar, electrical engineering, quality, or related technical fields (PV experience strongly preferred). - Mandarin speaking is a plus. - Strong analytical skills with basic understanding of quality or engineering fundamentals. - Proven ability to manage cross-functional collaboration and complex technical issues. - Excellent written and verbal communication skills. - Proficiency in Microsoft Office Suite (Excel, Word, PowerPoint, Outlook). - Ability to analyze issues, evaluate potential risks, and support problem-solving efforts. - Ability to participate in occasional off-hours meetings with HQ or other regions. - Ability to support multi-tasking in a fast-paced environment. Education or Desired License and Certificates - Bachelor’s degree in engineering, Quality, or related technical discipline, or equivalent practical experience. Competencies - Strong problem-solving and analytical thinking. - Strong ownership and accountability mindset. - Effective stakeholder communication and influence. - Organized, detail-oriented, and proactive. - Interest or experience in risk assessment and change management. - Ability to work independently while supporting cross-functional teams. - Ability to operate in a fast-paced, global environment. Travel - About 20%. Work Location and Status - Contract role. - Remote work available in TX. - For candidates in the states of California, Colorado, New York, and Washington, the anticipated annual base salary for this role is between $103,000 - $140,000. This range does not include any other compensation components or other benefits that an individual may be eligible for. The base salary offered is dependent upon several factors, including but not limited to job-related skills, qualifications, experience, education, location, or other factors related to the role. Sungrow is an equal opportunity employer. Due to strong interests in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.
Machine Learning Engineer, Ads Optimization – Ads Marketplace Quality
RedditReddit is an online platform utilized by thousands of communities to connect and converse about a wide variety of topics, including TV and movie fan theories, s
• Design and implement optimization algorithms for auctions, bidding strategies, and pacing that balance advertiser performance, user experience, and marketplace efficiency. • Own systems end-to-end: from problem formulation and algorithm design to experimentation, production deployment, and ongoing iteration. • Work across Ads Optimization (bid strategies, budget optimization, pacing) or Ads Marketplace Quality (ad matching, ad load, quality controls) to deliver measurable wins for advertisers and Redditors.
Senior Quality Assurance Analyst, Automation
Goods & ServicesMaking things better by making better things
• Develop and maintain automated test scripts using Selenium. • Perform API testing with Postman. • Create and manage test cases with Tricentis. • Validate test data and backend processes using SQL. • Collaborate with teams to ensure quality and test coverage.
• Write and manage software integration and regression test cases. • Develop and maintain the testing infrastructure for core healthcare products. • Leverage AI tools to accelerate and automate testing. • Collaborate with cross-functional teams to integrate products with business processes and backend infrastructure. • Work on a variety of products, demonstrating flexibility and adaptability. • Ensure the scalability, performance, and security of developed solutions. • Participate in code reviews, contributing to and maintaining high code quality. • Stay up-to-date with emerging technologies and industry best practices.



