Job Closed

This listing is no longer active.

Stratascale logo
Stratascale

Secure the Digital Future

Senior Security Consultant – Penetration Testing

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 201-500Since 2020H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

141 days ago

Salary

$165K - $205K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglish

Job Description

Senior Security Consultant – Penetration Testing

Stratascale

• Perform penetration testing against complex environments covering both external, internal, web application, and other forms of offensive security engagements • Consult and document attack surface, threats, and vulnerability improvements based on team’s overall assessment of client’s environment • Perform full assessment and threat modeling against industry best practices to identify control weaknesses and assess the effectiveness of existing controls • Perform root cause analysis on identified vulnerabilities and attack surface weaknesses to determine technical solutions to be presented to client along with recommendations for remediations • Collaborate with client’s security teams to understand mitigation or resolutions for findings discovered by analysts • Review threat intelligence for specific threat vectors that align with client's industry or potentially impacted by to utilize in attack path modeling • Assist in defining, measuring, and quantifying business risk and vulnerability impacts to clients and their stakeholders • Provide subject matter expertise and technical support on remediation, cloud security, governance, compliance, and core infrastructure systems • Assist customers with strategies, use of platforms, technical and compliance analysis, and implementing automation • Develop and deliver governance models, security frameworks, compliance reporting, and security assessments • Collaborate with internal sales and technical teams to support the solution sales cycle, qualify opportunities, and ensure successful solution delivery • Identify customer needs and requirements, recommend appropriate solutions, and proactively identify areas for improvement • Execute consulting projects by creating and completing deliverables, ensuring client needs and practice obligations are met • Develop and deliver training content, curricula, and workforce development programs, including in-person and remote sessions • Participate in customer and internal meetings, providing technical guidance and facilitating discussions • Stay educated on new product technologies, industry trends, and emerging capabilities within the practice • Develop and optimize cross practice capabilities, collaborate with peer practice leaders, and mentor other consultants.

Job Requirements

  • Completed Bachelor’s Degree in a related field or relevant work experience required
  • 5–7 years of hands-on penetration testing/red team experience delivering engagements for mid-to-large enterprises, including leading complex assessments
  • Ability to travel to SHI, Partner, Customer events, and on-site testing engagements as needed
  • Advanced industry certifications preferred (e.g., OSCP, OSEP, OSWE, GXPN, GPEN, CRTO, CRTP, PNPT; CISSP or CSSLP a plus)
  • Demonstrated understanding of legal/ethical considerations, testing authorization, and safe handling of client data.

Benefits

  • medical
  • vision
  • dental
  • 401K
  • flexible spending

Related Categories

Related Job Pages

More Security Engineer Jobs

softsich logo

Security Engineer

softsich

We are a young, ambitious, and fast-growing company that creates innovative digital products and is confidently expanding its presence in global markets.

Security Engineer141 days ago

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role involves strengthening our internal infrastructure and helping automate key security workflows. - Monitor and analyze security alerts across multiple security platforms (SIEM, EDR, SOAR) - Lead Incident Response - serve as primary responder to security alerts, perform initial triage, conduct investigations, and coordinate remediation - Enhance Detection Capabilities - design, implement, and fine-tune detection rules and alerts across cloud environments - Conduct endpoint, network, and application log analysis to identify suspicious activity - Collaborate with IT, DevOps, and Compliance teams to enforce security standards and best practices - Assist in improving incident response processes, playbooks, and operational practices - Stay informed about emerging cybersecurity threats, trends, and industry developments - Deploy and manage MDM/UEM solutions (Jamf, Jumpcloud) across all endpoints - Advocate for best practices in IT and change management to strengthen security posture - Define and enforce security policies for workstations (passwords, encryption, restrictions, app controls) - Perform regular audits and compliance checks aligned with corporate standards - Monitor device health and security compliance, respond to related alerts - Coordinate patching and updates on endpoints through MDM - Conduct inventory and asset tracking, including remote wipe and lock management - Provide endpoint security reporting and metrics to IT leadership and compliance - Collaborate with incident response teams on mobile endpoint incidents Qualifications - 3+ years in IT Operations, System Administration, or related roles - Experience in security threat analysis or incident response, ideally within a SOC - Proven experience responding to and managing incidents in cloud environments (AWS, Azure, GCP) and SaaS services (Google Workspace, Atlassian) - Proficiency with SIEM platforms, including rule creation, tuning, and maintenance - Strong knowledge of cloud security monitoring tools and techniques - Understanding of network infrastructure - Experience analyzing endpoint, network, and application logs for anomalies - Practical understanding of common attack vectors and how to detect them - Experience with security automation and scripting for incident response workflows - Understanding of IT system architecture, network design, and IT/change management processes - Experience with virtualization technologies - Familiarity with identity management - Proficiency in platforms used for information security investigations and triage Requirements - Experience with cloud-native security tools and services - Familiarity with scripting or automation (PowerShell, Bash, Python) - Experience with endpoint detection solutions and email security technologies - Knowledge of IT security audit techniques Benefits - A competitive salary - Remote work format or a modern office in Warsaw and/or Kyiv - Flexible working hours - An incredibly friendly team where everyone is ready to share knowledge, help, and support - 24 working days of paid annual vacation - Paid sick leave - Health insurance (available for specialists based in Ukraine; other countries — in progress) - Zero joules of energy to the aggressor state, its affiliated businesses, or partners - Conference and business travel expenses covered (where applicable) - Birthday greetings (because you matter!) - Online and offline teambuilding events - Corporate celebrations

United States + 171 moreAll locations: United States | Canada | Brazil | Colombia | Argentina | Chile | Venezuela | Bolivia | Ecuador | French Guiana | Guyana | Paraguay | Peru | Suriname | Uruguay | Mexico | Costa Rica | El Salvador | Guatemala | Honduras | Nicaragua | Panama | Dominican Republic | Puerto Rico | Bahamas | Guadeloupe | Haiti | Jamaica | Martinique | Montserrat | United Kingdom | Germany | France | Estonia | Portugal | Hungary | Poland | Ukraine | Romania | Bulgaria | Czechia | Slovakia | Belarus | Moldova | Sweden | Greece | Belgium | Italy | Ireland | Switzerland | Netherlands | Finland | Malta | Denmark | Lithuania | Croatia | Spain | Austria | Bosnia And Herzegovina | Iceland | Luxembourg | North Macedonia | Montenegro | Norway | Serbia | Slovenia | Albania | Cyprus | Latvia | Monaco | South Africa | Egypt | Algeria | Angola | Benin | Botswana | Burkina Faso | Burundi | Cameroon | Cabo Verde | Central African Republic | Chad | Congo | Côte D'ivoire | Democratic Republic of the Congo | Equatorial Guinea | Eritrea | Ethiopia | Gabon | Gambia | Ghana | Guinea | Guinea-bissau | Kenya | Lesotho | Liberia | Libya | Madagascar | Malawi | Mali | Mauritania | Mauritius | Mayotte | Morocco | Mozambique | Namibia | Niger | Nigeria | Réunion | Rwanda | Senegal | Seychelles | Sierra Leone | Somalia | Sudan | Eswatini | Tanzania | Togo | Tunisia | Uganda | Zambia | Zimbabwe | Georgia | Turkey | Israel | United Arab Emirates | Armenia | Azerbaijan | Bahrain | Iraq | Jordan | Kuwait | Lebanon | Oman | Qatar | Saudi Arabia | Palestine | Yemen | India | Japan | Philippines | Pakistan | Thailand | Singapore | Vietnam | Taiwan | Indonesia | Cambodia | Laos | Malaysia | Myanmar | South Korea | China | Afghanistan | Bangladesh | Bhutan | Kazakhstan | Kyrgyzstan | Maldives | Mongolia | Nepal | Sri Lanka | Tajikistan | Turkmenistan | Uzbekistan | Australia | Papua New Guinea | Kiribati | Palau | French Polynesia | Tuvalu | New Zealand
Job Closed
Full TimeRemoteTeam 10,001+Since 1978H1B No Sponsor

• Design, review and execute solutions to protect the enterprise; • Lead, mentor and provide guidance; • Facilitate vulnerability management programs across systems, networking and engineering teams; • Develop, test, deploy and operationalize security monitoring, assessment and response solutions

United States
$140K - $220K / year
Job Closed
OtherRemoteTeam 10,001+Since 1876H1B Sponsor

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world. What You'll Be Doing As a Security Architect, you will serve as a technical lead for security consulting engagements, threat modeling initiatives, and third-party security assessments. You will develop threat models, security architectures, and reference patterns — including for cloud and hybrid environments — while providing guidance on secure design principles. This role involves close collaboration across teams to integrate security into the development lifecycle and evaluate vendor security posture. You will also leverage AI-powered tools to enhance the efficiency and depth of security assessments. How You'll Succeed - Technical expertise: Deep domain knowledge across security engineering, threat modeling, cloud architectures, application security, and third-party risk management. Ability to use AI tooling to accelerate and improve security work. - Strategic thinking: Ability to develop reference architectures and integrate complex systems across on-premises and cloud environments, balancing security risk with business enablement. - Consultative approach: Provide expert security guidance to teams, stakeholders, and external vendors throughout assessment engagements, including evaluating and advising on the secure use of AI platforms. - Leadership: Lead technical initiatives and architecture reviews while mentoring junior security professionals. - Innovation: Actively promote cloud-native security patterns and the responsible adoption of AI technologies across teams. - Communication: Translate complex security concepts and technical risk findings into clear, business-friendly language for executive stakeholders and audiences with different technical backgrounds. Key Responsibilities - Develop and conduct threat modeling exercises across application, infrastructure, and cloud environments using established frameworks (MITRE ATT&CK, STRIDE, NIST 800-53, ISO 27001) - Create and maintain security architectures and design patterns, including cloud and hybrid reference architectures - Conduct security architecture reviews for internal initiatives, new technologies, and third-party vendors. - Perform third-party security assessments, including vendor questionnaire reviews, SOC 2 evaluations, and risk acceptance documentation - Leverage AI tools and technologies to streamline assessment workflows, analyze vendor documentation, identify risk patterns, and improve assessment quality and consistency - Provide security consulting services across the organization, enabling business objectives while clearly communicating risk - Develop and document security best practices, standards, and guidance — including responsible AI tool usage in security workflows - Lead security briefings and workshops; mentor junior security engineers and drive adoption of security standards Your Basic Qualifications - High Schol Diploma/GED - Deep expertise in threat modeling methodologies and security architecture design across cloud (AWS, Azure, GCP), SaaS, and hybrid environments - Strong background in security consulting, risk assessment, and third-party cyber risk management, including SOC 2 review and HIPAA compliance evaluation - Minimum seven years of cybersecurity or related experience - Qualified applicants must be authorized to work in the United States on a full-time basis. Lilly will not provide support for or sponsor work authorization or visas for this role now or in the future, including but not limited to F-1 CPT, F-1 OPT, F-1 STEM OPT, J-1, H-1B, TN, O-1, E-3, H-1B1, or L-1. What You Should Bring - Bachelor's degree in Computer Science, Information Security, or related field preferred - Experience with or willingness to adopt AI tools for document analysis, risk summarization, and pattern identification; understanding of AI/ML security considerations - Knowledge of Zero Trust principles and major security frameworks (MITRE ATT&CK, STRIDE, NIST 800-53, ISO 27001) - Excellence in technical documentation and executive-level risk communication - Experience mentoring, collaborating across teams, and engaging stakeholders at varying levels of technical expertise - Project management and strategic planning skills - Commitment to continuous learning and professional development, including staying current on developments relevant to cybersecurity Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response. Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status. Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia Network, Black Employees at Lilly, Chinese Culture Network, Japanese International Leadership Network (JILN), Lilly India Network, Organization of Latinx at Lilly (OLA), PRIDE (LGBTQ+ Allies), Veterans Leadership Network (VLN), Women’s Initiative for Leading at Lilly (WILL), enAble (for people with disabilities). Learn more about all of our groups. Actual compensation will depend on a candidate’s education, experience, skills, and geographic location. The anticipated wage for this position is $141,000 - $246,400 Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees. #WeAreLilly

United States
$141K - $246K / year
Job Closed
Businessolver logo

Information Security Architect

Businessolver

Benefits Technology, Powered by People

Security Engineer141 days ago
OtherRemoteTeam 1,001-5,000Since 1998H1B Sponsor

Since 1998, Businessolver has delivered market-changing benefits technology and services supported by an intrinsic responsiveness to client needs. The company creates client programs that maximize benefits program investment, minimize risk exposure, and engage employees with easy-to-use solutions and communication tools to assist them in making wise and cost-efficient benefits selections. Founded by HR professionals, Businessolver's unwavering service-oriented culture and secure SaaS platform provide measurable success in its mission to provide complete client delight. The Information Security Architect is responsible for designing and implementing secure systems, networks, and applications to protect the organization’s data and technology assets. This role maintains compliance with Businessolver’s security framework, policies, and standards, ensuring security is built into systems from the ground up. Responsibilities include assessing risks, identifying vulnerabilities, selecting appropriate security technologies, and guiding teams on secure design principles. This role will partner closely with IT, engineering, and business leaders to balance security requirements with operational and business needs, ensuring resilience against evolving cyber threats. At Businessolver you have opportunities for individual development through our common language: Respond Readily. Trust through transparency. Assume positive intent. Be real. Live a growth attitude. Embrace the reverse golden rule. Essential Duties: - Ensure all security practices, systems, and architectures adhere to applicable laws, regulations, frameworks, and industry standards. - Maintain documentation to demonstrate compliance and support audits. - Develop and document secure technical architectures that integrate cybersecurity best practices into enterprise systems, applications, and cloud environments. - Balance security requirements with business needs to enable scalable, resilient solutions. - Engineer and implement security controls for systems, applications, and networks to safeguard against unauthorized access, data breaches, and service disruptions. - Conduct risk assessments to identify potential vulnerabilities and apply appropriate mitigations. - Partner with infrastructure, operations, and development teams to embed security throughout the technology lifecycle. - Provide guidance during planning, design, development, testing, and deployment to ensure secure-by-design outcomes. - Perform and coordinate penetration testing, vulnerability scanning, code reviews, and other security validation activities. - Interpret results, recommend remediation strategies, and ensure corrective actions are effectively implemented. - Establish monitoring processes, tools, and dashboards to proactively detect and respond to anomalies or threats. - Continuously assess and refine security controls, processes, and technologies to address evolving risks and improve maturity. - Assist in the identification, investigation, containment, and recovery of security incidents. - Provide technical expertise to incident response teams and contribute to post-incident reviews to strengthen defenses and reduce recurrence. - Performs other duties as assigned. - Comply with all policies and standards - Qualifications: - Bachelor's degree (Computer Science, Information Technology, Cybersecurity, Information Assurance, Information Systems) - Master’s degree preferred in Cybersecurity, Information Assurance, or Business Administration - Certifications One required, Multiple preferred (CISSP, CISM, CISA, CEH, Security+, CCSP, TOGAF) - 5-10 years of IT and Security Experience - 2-4 years of cloud computing security experience - 5 years of demonstrated experience designing and implementing security Solutions - 5 years of experience interacting with business partners to achieve security goals The pay range for this position is $89K to $149K per year (pay to be determined by the applicant’s education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data). This role is eligible to participate in the annual bonus incentive plan. Interested? Great, we look forward to reviewing your application. Other Compensation: If this position is full-time or part-time benefit eligible, you will receive a comprehensive benefits package which can be viewed here: https://businessolver.foleon.com/bsc/job-board-businessolver-virtual-benefits-guide/ Dear Applicant. At Businessolver, we take our responsibility to protect our clients, employees, and company seriously and that begins with the hiring process. Our approach is thoughtful and thorough. We’ve built a multi-layered screening process designed to identify top talent and ensure the integrity of every hire. This includes quickly filtering out individuals who may attempt to misrepresent themselves or act in bad faith. We also partner with trusted, best-in-class providers to conduct background checks, verify identities, and confirm references. These steps aren’t just about compliance, they’re about ensuring fairness, safety, and trust for everyone involved. Put simply: we will always confirm that you are who you say you are. It's just one of the many ways we uphold the standards that matter most, to you, to us, and to the people we serve. With heart, The Businessolver Recruiting Team Businessolver is committed to maintaining an environment that protects client data. We train our employees to maintain leading class security practices and expect all employees to adhere to policy, procedures and controls. (Applicable to all roles at an AVP, DIR, VP, Head Of or SVP and above level): Serve as a security contact for the business unit. Responsible for driving adoption and compliance with information security and privacy practices. Serve as a liaison with the information security team on security and privacy matters. Equal Opportunity at Businessolver: Businessolver is an Affirmative Action and Equal Opportunity Employer and is proud to offer equal employment opportunity to everyone regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, and more. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. #LI-Remote

United States
$65K - $75K / year
Job Closed