Penetration Tester

Vertiv

Mandaluyong

On-site

PHP 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Continuous development opportunities
Mentorship and leadership guidance
Inclusive workplace culture

Job summary

Vertiv is looking for an Analyst II | Application and Product Security to conduct security evaluations and penetration tests on embedded devices and cloud services. This role requires collaboration with engineering teams and the ability to document findings effectively.

The ideal candidate holds a degree in Information Technology and possesses advanced security qualifications with several years of relevant experience. Opportunities for growth and professional development are integral to the company culture.

Qualifications

  • Three or more years of experience in application and product security.
  • Strong understanding of IT risks and security solutions.
  • Ability to interact with different personnel to enforce security measures.

Responsibilities

  • Conduct security evaluations of embedded systems and applications.
  • Reverse engineer complex systems and create technical reports.
  • Provide proactive interaction with engineering groups on testing needs.

Skills

Security protocols
Cryptography
Excellent communication skills
Leadership
Technical contributions

Education

Bachelor's degree in Information Technology or related field
CISSP or equivalent

Tools

Git
IDA Pro
WinDbg
Metasploit
Nessus

Job description

Job Description

Join a High-Performance Culture That Drives Innovation and Excellence

Why Vertiv?
  • High-Performance Culture: We empower you to think big, execute with excellence, and deliver impact. Our performance-driven mindset rewards those who challenge the status quo and drive meaningful change. Over 50 CEO Awards are given annually to recognize top talent moving the needle forward.
  • Leadership Without Limits: Leadership at Vertiv goes beyond just titles—it’s about accountability, trust, and ownership. Our leaders engage and drive with collaboration, innovation, and customer-centric thinking, setting the foundation for an action-focused culture.
  • Limitless Growth & Learning: We believe in continuous development. Whether through rotational programs or high-impact projects, you’ll have the opportunity to expand your expertise and grow your career.
  • A Place for Everyone: Our commitment to inclusion ensures that all employee’s unique strengths and perspectives are valued. Your voice matters, your growth is prioritized, and your success is celebrated.
Role Overview

The Analyst II | Application and Product Security is responsible for conducting security pen testing, monitoring, and auditing within a dynamic global organization. The products under test will have coverage of embedded devices and cloud services. The Senior Pen Tester should have exposure to embedded devices as well as cloud services (AWS/Azure). Some of the products will be white box tests while others will be total black box engagements. A successful Senior Pen Tester will be able to evaluate the weak points in the design and implementation, focus on those weaknesses to find security gaps, and clearly document and relay findings to the design team for mitigation. The Senior Pen Tester will need to be very versatile in attack vectors and knowledge of exploits. The ideal candidate will be well experienced in a broad range of attack vectors across a wide spectrum of devices from small, embedded devices to complex cloud ecosystems. They will be responsible for interfacing with engineering teams to conduct security testing, auditing, and explaining findings. They will ensure engineering teams stay in compliance with the global organization’s security expectations. The Senior Pen Tester will stay current with the latest security threats and attack vectors, communicate findings clearly, and enhance internal testing processes and procedures.

Job Responsibilities
  • Conduct security evaluation and threat assessments of embedded systems, mobile applications, web applications.
  • Conduct research to find new vulnerabilities and enhance existing capabilities.
  • Circumvent security protection methods and techniques.
  • Perform data bus monitoring (snooping) and data injection.
  • Conduct communications protocol analysis in embedded products and applications.
  • Conduct wireless communications channel snooping and data injection.
  • Reverse engineer complex systems and protocols.
  • Create detailed technical reports and proof‑of‑concept code to document findings.
  • Perform system breakdown of the project/product before testing, identify and evaluate all testing requirements, and plan testing activities and resources.
  • Provide proactive detailed interaction with engineering groups on testing needs, progress, status, and detailed analysis reports.
  • Manage Gitlab issue tracking, provide mentorship and direction on testing activities for junior resources, assist in leading testing activities in all regions, provide support to the Assessment Pillar Manager, and drive continuous improvement in testing processes.
  • Ensure thorough adherence to VERTIV SECURE requirements and Vulnerability Management and Incident Response processes.
  • Preference given to practical skills such as functional analysis, memory image capture, static memory analysis, and data element extraction.
Job Requirements
  • A bachelor’s degree in information technology, Computer Science or related engineering field is highly desirable.
  • Advanced security qualifications such as CISSP, Offensive Security Web Expert (OSWE) or equivalent preferred.
  • Three or more years’ experience in information, application, and embedded product security and/or IT risk management with a focus on security, performance, and reliability.
  • Solid understanding of security protocols, cryptography, authentication, authorization, and security.
  • Good working knowledge of current IT risks and experience implementing security solutions.
  • Ability to interact with a broad cross-section of personnel to articulate and enforce security measures.
  • Excellent written and verbal communication skills and business acumen.
  • Strong leadership, vision, effective communication, and goal orientation.
  • Strong ability to establish partnerships and influence change to achieve results within a dynamic environment.
  • Meaningful technical contributions to the development lifecycle of an application, product, or service.
Preferred Knowledge Experience Includes
  • Understanding and development experience of embedded systems/software and web-based applications.
  • Linux network device driver/data‑path performance exposure.
  • Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools.
  • Exposure to binary analysis tools such as IDA Pro, WinDbg, BinWalk, Valgrind, PIN, Panda, and S2E.
  • Working knowledge of hacking tools and techniques such as memory corruption exploits, rootkits, protocol poisoning, browser-based attacks, DNS poisoning, Metasploit, nmap, Nessus.
  • Experience with UNIX kernel internals and low-level Windows internals.
  • Comfort with reading and understanding x86 and/or ARM assembly.
  • Experience with program analysis techniques such as taint analysis, program slicing, symbolic execution, constraint solving, and dynamic instrumentation.
  • Understanding of common cryptographic algorithms and protocols, including weaknesses and attacks.
  • Ability to extract software/firmware from provided hardware.
  • Meaningful experience utilizing git (GitHub or GitLab).
  • Understanding of network protocols and experience developing packet-level programs.
  • Experience with common microcontroller programming tools and debugging interfaces.
  • Exposure to Layer 2, Layer 3 networking, QoS.
  • Network and/or application security knowledge (L2/L3 firewall, DPI, IDS, IPS).
  • Knowledge of common malware/botnet exploits and how they target embedded systems.
  • Operating system configuration of Windows, Linux, Android, and iOS.
  • Computer boot process including boot loaders.
  • Hands‑on real‑time embedded C/C++ development experience with recent lab activities integrating and debugging on target hardware.
About The Team

Work Authorization: No calls or agencies please. Vertiv will only employ those who are legally authorized to work in the United States. This position is not eligible for sponsorship.

Equal Opportunity Employer: We promote equal opportunities for all with respect to hiring, terms of employment, mobility, training, compensation, and occupational health, without discrimination as to age, race, color, religion, creed, sex, pregnancy status, marital status, sexual orientation, gender identity, genetic information, citizenship status, national origin, protected veteran status, political affiliation, or disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Vertiv Co • Mandaluyong

On-site
PHP 80,000 - 120,000
Continuous development opportunities
High-performance culture
Diversity and inclusion initiatives
Penetration Tester (Reverse Engineering and Embedded Code experience)
Penetration Tester (Reverse Engineering and Embedded Code experience)

Dencom Consultancy and Manpower Services • Mandaluyong

On-site
Senior Penetration Tester - Cloud & Embedded Security
Senior Penetration Tester - Cloud & Embedded Security

Vertiv • Mandaluyong

On-site
PHP 800,000 - 1,200,000
Continuous development opportunities
Mentorship and leadership guidance
Inclusive workplace culture
IT Security Trainee
IT Security Trainee

Vertiv • Mandaluyong

On-site
PHP 180,000 - 240,000
Sales Operations & Support Analyst
Sales Operations & Support Analyst

Vertiv • Mandaluyong

On-site
PHP 600,000 - 900,000
Associate Engineer Technical Publications VIII
Associate Engineer Technical Publications VIII

Vertiv Co • Mandaluyong

On-site
Penetration Tester
Penetration Tester

Our Clients • Manila

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester
Penetration Tester

Create Synergies Inc. • Manila

On-site
PHP 700,000 - 1,100,000
IT Database Administration Senior Coordinator (Commercialization Change Order)
IT Database Administration Senior Coordinator (Commercialization Change Order)

Vertiv • Mandaluyong

On-site
PHP 400,000 - 700,000
Associate Engineer Reliability Engineering VIII
Associate Engineer Reliability Engineering VIII

Vertiv • Mandaluyong

On-site
PHP 300,000 - 540,000