Penetration Tester

Vertiv Group Corporation

Mandaluyong

On-site

PHP 900,000 - 1,500,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Vertiv Philippines is seeking a Senior Pen Tester to conduct security testing across embedded devices and cloud services (AWS/Azure). The role requires evaluating design weaknesses and clearly reporting findings to the engineering teams for mitigation.

You will stay current with security threats, lead testing activities, and help evolve internal testing processes while mentoring junior staff. Strong communication and hands-on security expertise are essential.

Qualifications

  • Bachelor’s degree in information technology, Computer Science or related Engineering field.
  • Advanced security qualifications such as CISSP (Certified Information Systems Security Professional) or OSWE preferred.
  • Three or more years’ experience in information, application, and embedded product security and/or IT risk management.
  • Solid understanding of security protocols, cryptography, authentication, authorization, and security.
  • Ability to interact with a broad cross-section of personnel to articulate and enforce security measures.
  • Excellent written and verbal communication skills and leadership capabilities.
  • Hands-on experience with embedded systems and cloud services.

Responsibilities

  • Conduct security evaluation and threat assessments of embedded systems, mobile apps, and web apps.
  • Research to find new vulnerabilities and enhance existing capabilities.
  • Circumvent security protection methods and techniques.
  • Perform data bus monitoring and data injection as needed.
  • Analyze communications protocols in embedded products and applications.
  • Snoop wireless channels and perform data injection where applicable.
  • Reverse engineer complex systems and protocols.
  • Create detailed technical reports and proof-of-concept code to document findings.
  • Plan testing activities and coordinate with engineering teams to meet security requirements.
  • Mentor junior resources and drive testing process improvements across regions.

Skills

Penetration testing
Embedded devices
Cloud security
Threat assessment
Security auditing
GitLab
Reverse engineering
Threat modeling
Communication
Vulnerability management

Education

Bachelor’s degree in IT/CS/Engineering
CISSP
OSWE

Tools

IDA Pro
WinDbg
BinWalk
Valgrind
PIN
Panda
S2E

Job description

Join a High-Performance Culture That Drives Innovation and Excellence

At Vertiv, we don’t just hire talent—we cultivate leaders who drive innovation and engage teams to push the limits of what’s possible. As a global leader in critical digital infrastructure, we are scaling up to meet the demands of AI, data centers, and next-gen technology—and we need bold, high-performing individuals like YOU to take us to the next level.

Why Vertiv?
  • High-Performance Culture: We empower you tothink big, execute with excellence, and deliver impact. Ourperformance-driven mindset rewards those who challenge the status quo and drive meaningful change. Over50 CEO Awards are given annually to recognize top talent moving the needle forward.
  • Leadership Without Limits: Leadership at Vertiv goes beyond just titles—it’s about accountability, trust, and ownership. Our leadersengage and drive withcollaboration, innovation, and customer-centric thinking, setting the foundation for anaction-focused culture.
  • Limitless Growth & Learning: We believe in continuous development. Whether throughrotational programs or high-impact projects, you’ll have the opportunity toexpand your expertise and grow your career.
  • A Place for Everyone:Our commitment toinclusion ensures that all employee’s unique strengths and perspectives are valued.Your voice matters, your growth is prioritized, and your success is celebrated.
ROLE OVERVIEW

The AnalystII | Application and Product Security is responsible for conducting security pen testing, monitoring, and auditing within a dynamic global organization. The products under test will have the coverage of embedded devices and cloud services. The Senior Pen Tester should have exposure to embedded devices as well as cloud services (AWS/Azure). Some of the products will be white box tests while others will be total black box engagements. A successful Senior Pen Tester will be able to take the product and evaluate the weak points in the design and implementation and focus in on those weaknesses to find security gaps. All the findings by the Senior Pen Tester will need to be clearly documented and relayed to the design team for mitigation. The Senior Pen Tester will need to be very versatile in their attack vectors and their knowledge of exploits. The ideal candidate will be well experienced in a broad range of attack vectors across a wide spectrum of devices from small, embedded devices to wide and complex cloud ecosystems.

They will be responsible for interfacing with engineering teams to conduct security testing, auditing and should be able to explain the findings. They will be responsible for ensuring that engineering teams stay in compliance with the security expectations of the global organization. The Senior Pen Tester will be expected to stay current with the latest security threats and attack vectors that can be deployed against the product portfolio. They should also have experience in communicating clearly and concisely the findings of these activities to an audience.

The testing activity and methodology deployed to confirm compliance is guided but expected to be enhanced by the Senior Pen Tester. The Senior Pen Tester will be expected to use their knowledge and experience to further develop internal testing processes and procedures.

JOB RESPONSIBILITIES
  • Conduct security evaluation and threat assessments of embedded systems, mobile applications, web applications
  • Conduct research for the purposes of finding new vulnerabilities and enhancing existing capabilities
  • Circumventing security protection methods and techniques
  • Performing data bus monitoring (snooping) and data injection
  • Conduct communications protocol analysis in the embedded products, and applications
  • Conduct wireless communications channel snooping, and data injection
  • Reverse engineering complex systems and protocols
  • Create detailed technical reports and proof of concept code to document findings
  • Perform System Breakdown of the project/product before testing, identify and evaluate all the testing requirements and plan out the detailed testing activities, resources etc.
  • Proactive detailed interaction with respective engineering group on the testing needs, testing progress/status and provide detailed analysis report
  • Have effective Gitlab issue management reviewing and, providing mentorship and direction on planned testing activities for junior resources in line with defined processes and procedures. Assist in leading testing activities in all the regions, provide head-to-head support to Assessment Pillar Manager and help to drive continuous improvement in testing processes and procedures.
  • Thorough adherence and follow-up of VERTIV SECURE requirements and Vulnerability Management and Incident Response processes.
  • Preference given to other practical skills such as functional analysis, memory image capture, static memory analysis, and data element extraction, etc.
JOB REQUIREMENTS
  • A bachelor’s degree in information technology, Computer Science or related Engineering field is highly desirable.
  • Additional advanced security qualifications such as CISSP (Certified Information Systems Security Professional) certification, Offensive Security Web Expert (OSWE) or equivalent preferred.
  • Three or more years’ experience in information, application, and embedded product security and/or IT risk management with a focus on security, performance, and reliability
  • Solid understanding of security protocols, cryptography, authentication, authorization, and security
  • Good working knowledge of current IT risks and experience implementing security solutions
  • Ability to interact with a broad cross-section of personnel to articulate and enforce security measures
  • Excellent written and verbal communication skills as well as business acumen
  • Strong leadership, vision, effective communication and goal-oriented
  • Strong ability to establish partnerships and influence change and achieve results within dynamic environment
  • Meaningful technical contributions into the development lifecycle of an application, product, or service
Preferred knowledge experience includes
  • Understanding and development experience of embedded systems / software, and web-based applications
  • Linux network device driver/data-path performance exposure
  • Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools
  • Exposure to binary analysis tools such as IDA Pro, WinDbg, BinWalk, Valgrind, PIN, Panda, and S2E
  • Working knowledge of hacking tools and techniques such as memory corruption exploits, rootkits, protocol poisoning, browser-based attacks, DNS poisoning, MetaSploit, nmap, Nessus, etc.
  • Experience with UNIX kernel internals and low-level Windows internals
  • Comfort with reading and understanding of x86 and/or ARM assembly
  • Experience with program analysis techniques such as taint analysis, program slicing, symbolic execution, constraint solving, and dynamic instrumentation
  • An understanding of common cryptographic algorithms and protocols including their weaknesses and attacks against them
  • Ability to extract software/firmware from provided hardware
  • Meaningful experience utilizing git (Github or gitlab)
  • Understanding of network protocols and experience developing packet-level programs
  • Experience with common microcontroller programming tools and debugging interfaces
  • Linux network device driver/data-path performance exposure
  • Exposure to Layer 2, Layer 3 networking, QoS
  • Network and/or application security knowledge (L2/L3 firewall, DPI, IDS, IPS)
  • Knowledge of common malware/botnet exploits and how they are targeted to exploit embedded systems
  • Operating system configuration of Windows, Linux, Android, and iOS
  • Computer boot process including boot loaders
  • Conducting security evaluation and threat assessments of embedded systems, mobile applications, web applications
  • An understanding of common cryptographic algorithms and protocols including their weaknesses and attacks against them
  • Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools
  • Having hands on real-time embedded C/C++ development experience that includes recent lab activities integrating with and debugging on target hardware.

The successful candidate will embrace Vertiv’s Core Principals & Behaviors to help execute our Strategic Priorities.

OUR CORE PRINCIPALS: Safety.Integrity. Respect.Teamwork. Diversity & Inclusion.

OUR STRATEGIC PRIORITIES

  • Customer Focus
  • Operational Excellence
  • High-Performance Culture
  • Innovation
  • Financial Strength

OUR BEHAVIORS

  • Think Big and Execute
  • Act With Urgency
  • Own It
  • Drive Continuous Improvement
  • Promote Transparent and Open Communication
  • Learn and Seek Out Development
  • Foster a Customer-First Mindset
  • Lead by Example

#LI-DS5

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Vertiv • Mandaluyong

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester
Penetration Tester

Vertiv Co • Mandaluyong

On-site
PHP 80,000 - 120,000
Continuous development opportunities
High-performance culture
Diversity and inclusion initiatives
Security Platform Engineer (SIEM/SOAR, EDR, Google Sec Ops)
Security Platform Engineer (SIEM/SOAR, EDR, Google Sec Ops)

Vertiv • Mandaluyong

On-site
PHP 1,000,000 - 1,800,000
Security Engineering Engineer III
Security Engineering Engineer III

Vertiv Co • Mandaluyong

On-site
PHP 900,000 - 1,200,000
Equal opportunity employer
Penetration Tester (Reverse Engineering and Embedded Code experience)
Penetration Tester (Reverse Engineering and Embedded Code experience)

Dencom Consultancy and Manpower Services • Mandaluyong

On-site
PHP 892,800 - 1,116,000
Associate Engineer Technical Publications VIII
Associate Engineer Technical Publications VIII

Vertiv Co • Mandaluyong

On-site
PHP 334,800 - 613,800
Security Engineering Engineer III
Security Engineering Engineer III

Vertiv Group Corporation • Mandaluyong

On-site
PHP 900,000 - 1,400,000
Security Engineering Engineer III
Security Engineering Engineer III

Vertiv • Mandaluyong

On-site
PHP 600,000 - 900,000
Quality Assurance Analyst (Sales Operations)
Quality Assurance Analyst (Sales Operations)

Vertiv • Mandaluyong

On-site
PHP 480,000 - 720,000
Application and Product Security II Engineer II
Application and Product Security II Engineer II

Vertiv Group Corporation • Mandaluyong

On-site
PHP 13,392,000 - 20,088,000