Security Assurance Penetration Tester

RXinsider LTD.

Northern (KY)

Hybrid

USD 72,000 - 119,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Elsevier is seeking a collaborative Penetration Tester to support the offensive security function within Security Engineering. You will perform hands-on testing, validate vulnerabilities, and help automate security assurance processes in a fast-paced environment.

The role supports third-party assessment programs, reviews findings with development teams, and contributes to GenAI security testing, including LLMs and AI agents. A relevant security certification is preferred.

Qualifications

  • Hands-on information security testing experience or related coursework.
  • Certifications such as Security+, PNPT, CEH or OSCP are a plus.
  • Foundational web app, network, and OS security knowledge.

Responsibilities

  • Perform penetration testing of web apps, APIs, cloud, and internal systems.
  • Triages findings from third-party assessments and tracks remediation.
  • Collaborates with product and dev teams to communicate risks.
  • Review testing deliverables and support methodology selection.
  • Contribute to GenAI security testing practices and checklists.

Skills

Penetration testing
Vulnerability assessment
Security testing
Scripting (Python/Bash)
Team collaboration

Education

Security certification (e.g., Security+, PNPT, CEH)
Bachelor's in CS/IT or equivalent

Tools

Burp Suite
Nmap
Metasploit
Nuclei

Job description

Are you a collaborative Penetration Tester looking to work for a mission driven global organization?

About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands‑on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands‑on role for a motivated security professional eager to grow in a collaborative, fast‑paced environment.

About the team - The Security Assurance team supports the third‑party penetration testing program, security control validation, and ongoing offensive security testing activities.

Responsibilities
  • Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
  • Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
  • Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
  • Maintaining program documentation, test records, and reporting artifacts.
  • Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
  • Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
  • Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
  • Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
  • Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
  • Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
  • Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
  • At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
  • Foundational understanding of web application architecture, networking, and operating system security.
  • Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
  • Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
  • Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
  • Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
  • Exposure to SAST/DAST tools and secure code review practices is desirable.
  • Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)

Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.

Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer‑reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.

In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements.

U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates. If performed in Colorado, the base pay range is $71,600 - $119,400. If performed in New York, the base pay range is $78,700 - $131,400. If performed in New York City, the base pay range is $85,900 - $143,300. If performed in Rochester, NY, the base pay range is $71,600 - $119,400. If performed in New Jersey, the base pay range is $84,546 - $135,054. This job is eligible for an annual incentive bonus. Application deadline is 09/17/2026.

We know your well‑being and happiness are key to a long and successful career. We are delighted to offer country specific benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Sec Ops
Senior Security Engineer - Sec Ops

relx • New Jersey

On-site
USD 93,000 - 149,000
Annual incentive bonus
Country-specific benefits
Senior Security Engineer - Sec Ops
Senior Security Engineer - Sec Ops

RXinsider LTD. • New Jersey

On-site
USD 93,000 - 149,000
Senior Security Engineer - Sec Ops
Senior Security Engineer - Sec Ops

Socket.dev • New York (NY)

On-site
USD 95,000 - 158,000
Senior ML Ops Engineer
Senior ML Ops Engineer

RXinsider LTD. • Philadelphia

On-site
USD 95,000 - 159,000
AI Software Engineering Lead
AI Software Engineering Lead

RXinsider LTD. • Philadelphia

On-site
USD 115,000 - 192,000
Annual incentive bonus
Country-specific benefits
Senior ML Ops Engineer
Senior ML Ops Engineer

Elsevier • Philadelphia

On-site
USD 95,000 - 159,000
Senior ML Ops Engineer
Senior ML Ops Engineer

RELX • Philadelphia

On-site
USD 95,000 - 159,000
Senior Security Engineer - Sec Ops
Senior Security Engineer - Sec Ops

Elsevier • New Jersey

On-site
USD 93,000 - 149,000
Annual incentive bonus
Senior Security Engineer - Sec Ops
Senior Security Engineer - Sec Ops

LexisNexis Risk Solutions • New Jersey

On-site
USD 93,000 - 149,000
Manager, HRBP
Manager, HRBP

RXinsider LTD. • New York (NY)

On-site
USD 82,000 - 173,000
Country-specific benefits
Wellbeing initiatives
Parental leave
+2