Penetration Testing Engineer II

Jobtailor

Bentonville (AR)

On-site

USD 80,000 - 110,000

Full time

39 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Bentonville, Arkansas seeks a security testing professional to perform penetration tests and assess security controls across product teams.

You will document findings, contribute to risk assessments, and work with design teams to ensure security integrates with system designs and business requirements. Knowledge of cloud, networks, scripting, and accessibility standards is a plus.

Qualifications

  • Bachelor's or higher in a relevant IT/security field.
  • 3+ years of hands-on penetration testing experience.
  • Knowledge of security principles, frameworks, controls, and risk assessment.
  • Familiarity with secure coding, scripting, OS, networking, cloud and IoT/embedded.
  • Understanding of architectural design and security standards.
  • Preferred: Security+, Network+, GISF, or GSEC certifications.
  • Knowledge of WCAG 2.2 AA and accessibility best practices is a plus.

Responsibilities

  • Perform basic penetration and security testing using preconfigured tools and scripts.
  • Assist with reviewing and analyzing security control issues and identified vulnerabilities.
  • Apply security severity ratings with guidance.
  • Document security findings in workflow reporting tools and build knowledge of security testing tools.
  • Assist in designing solutions so security processes and applications work in tandem for product/system components and modules.
  • Evaluate design tradeoffs based on business requirements and support conversion of high-level designs into detailed module/component designs.
  • Adhere to security and compliance frameworks when creating designs.
  • Maintain updated logs and documentation of daily network performance.
  • Monitor performance data to ensure adherence to defined SLOs for simple network applications and systems.
  • Understand alerts generated by monitoring tools.
  • Assist in analyzing existing solutions against business or technical requirements.
  • Prepare and maintain requirement traceability matrices across business requirements, functional requirements, design, and test cases.
  • Contribute to user stories for components/modules and simple requirements.
  • Assist design teams in outlining parts of larger network infrastructure components and systems.
  • Provide expert advice and guidance on information and best practices.
  • Build stakeholder relationships, identify business needs, implement processes, monitor results, and pursue improvements.
  • Support company policies, mission, values, ethics, compliance, inclusion, collaboration, customer/member focus, and continuous improvement.

Skills

Penetration Testing
Security Frameworks
Network Monitoring Tools
Requirement Traceability Matrices
Security+ Certification

Education

Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area
3 years’ experience in penetration testing or related area at a technology, retail, or data-driven company

Tools

Workflow Reporting Tools
Monitoring Metrics
KPI
SLI
SLO

Job description


  • Perform basic penetration and security testing using preconfigured tools and scripts.

  • Assist with reviewing and analyzing security control issues and identified vulnerabilities.

  • Apply security severity ratings with guidance.

  • Document security findings in workflow reporting tools and build knowledge of security testing tools.

  • Assist in designing solutions so security processes and applications work in tandem for product/system components and modules.

  • Evaluate design tradeoffs based on business requirements and support conversion of high-level designs into detailed module/component designs.

  • Adhere to security and compliance frameworks when creating designs.

  • Maintain updated logs and documentation of daily network performance.

  • Monitor performance data to ensure adherence to defined SLOs for simple network applications and systems.

  • Understand alerts generated by monitoring tools.

  • Assist in analyzing existing solutions against business or technical requirements.

  • Prepare and maintain requirement traceability matrices across business requirements, functional requirements, design, and test cases.

  • Contribute to user stories for components/modules and simple requirements.

  • Assist design teams in outlining parts of larger network infrastructure components and systems.

  • Provide expert advice and guidance on information and best practices.

  • Build stakeholder relationships, identify business needs, implement processes, monitor results, and pursue improvements.

  • Support company policies, mission, values, ethics, compliance, inclusion, collaboration, customer/member focus, and continuous improvement.


Requirements


  • Option 1: Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area.

  • Option 2: 3 years’ experience in penetration testing or related area at a technology, retail, or data-driven company.

  • Knowledge of security principles, frameworks, methodologies, controls, risk frameworks, security testing techniques, secure coding frameworks and standards, scripting, operating systems, networking, mobile technology, cloud computing services, and IoT/embedded systems.

  • Knowledge of software architecture, distributed systems, scalability, design patterns, disaster recovery, tech stacks, nonfunctional requirements, security standards/frameworks/methodologies, SSP, SRCR, cloud platforms, IoT, and new software/hardware platform technologies.

  • Knowledge of network monitoring and alerting tools, monitoring metrics and KPIs, SLIs, and SLOs.

  • Knowledge of traceability matrices, risk analysis methodologies, cost analysis, business objectives, classification of requirements, and user stories.

  • Knowledge of architectural blueprint design, industry standards and best practices, network infrastructure topologies, platforms, and protocols.

  • Preferred: Certification in Security+, Network+, GISF, or GSEC.

  • Preferred: Knowledge of WCAG 2.2 AA standards, assistive technologies, and digital accessibility best practices.


Core Competencies

Demonstrates expertise in penetration testing, security frameworks, and compliance standards while effectively collaborating with design teams to ensure security processes align with business requirements. Proficient in documenting security findings and maintaining requirement traceability across various project components.


Highest-signal resume keywords


  • Penetration Testing

  • Security Frameworks

  • Network Monitoring Tools

  • Requirement Traceability Matrices

  • Security+ Certification


Hard Skills


  • Security Testing Techniques

  • Scripting

  • Operating Systems

  • Networking

  • Cloud Computing ServicesIoT/Embedded Systems

  • Software Architecture

  • Risk Analysis Methodologies

  • Design Patterns

  • Disaster Recovery


Soft Skills


  • Stakeholder Relationship Building

  • Collaboration

  • Continuous Improvement


Certifications & Qualifications


  • Security+

  • Network+

  • GISF

  • GSEC


Industry Keywords


  • Security Principles

  • Compliance Frameworks

  • Digital Accessibility Best Practices

  • WCAG 2.2 AA Standards

  • Network Infrastructure Topologies


Tools & Technologies


  • Workflow Reporting Tools

  • Monitoring Metrics

  • KPI

  • SLI

  • SLO

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Information Security Specialist – Regional
Information Security Specialist – Regional

Jobtailor • Missouri

On-site
USD 90,000 - 130,000
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Cybersecurity Analyst II
Cybersecurity Analyst II

Jobtailor • Reading

On-site
USD 90,000 - 120,000
Vulnerability Management Technical Lead
Vulnerability Management Technical Lead

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 230,000
Information Security Architect – Data Engineering, Security
Information Security Architect – Data Engineering, Security

Jobtailor • Alabama

On-site
USD 110,000 - 170,000
Director of Cyber Security
Director of Cyber Security

Jobtailor • Concord (MA)

Hybrid
USD 180,000 - 260,000
Cybersecurity Analyst
Cybersecurity Analyst

Jobtailor • Fort Meade (MD)

On-site
USD 85,000 - 135,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 170,000