Security Consultant - Penetration Testing & DevSecOps

Capgemini

Northern (KY)

Hybrid

USD 70,000 - 170,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision coverage
401(k) plan
Paid time off

Job summary

Capgemini is seeking a Senior Security Consultant for Penetration Testing & DevSecOps with 5-8 years of cybersecurity experience. The role focuses on security assessments across applications, APIs, cloud environments, and CI/CD pipelines, embedding security throughout the software development lifecycle.

The candidate will collaborate with development teams to remediate vulnerabilities, support threat modeling, and promote secure coding practices in modern architectures.

Qualifications

  • 5-8 years of hands-on cybersecurity experience.
  • Minimum 3+ years of experience conducting application and API penetration testing.
  • Experience implementing or supporting DevSecOps initiatives within CI/CD environments.

Responsibilities

  • Perform manual and automated penetration testing of web applications, APIs, mobile apps, cloud environments, and supporting infrastructure.
  • Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities following industry-standard methodologies.
  • Identify security vulnerabilities, validate exploitability, assess business risk, and provide remediation recommendations.
  • Execute security assessments against microservices, containers, Kubernetes, and cloud-native apps.

Skills

Web App Security
API Security
Secure SDLC
OWASP Top 10
MITRE ATT&CK
Threat Modeling
Vulnerability Management
Burp Suite
Nmap
Nessus/Qualys/Tenable
Metasploit
Kali Linux
Checkmarx
Veracode
Snyk
SonarQube
GitHub Actions/Azure DevOps/Jenkins

Education

Bachelor's degree in Computer Science, Information Security, Engineering, or a related field

Tools

Burp Suite Professional
Nessus
Qualys
Tenable
Metasploit
Kali Linux

Job description

# Security Consultant - Penetration Testing & DevSecOpsAlabama City, Atlanta, Austin, Bellevue, Berwyn, Bridgewater, Brooklyn, Burlington, Chicago, Cincinnati, Columbia, Creve Coeur, Dallas, Dayton - Sogeti US, Guaynabo, Houston, Irving, Mclean, Minneapolis, Minnesota City, Mission, Nashville, Needham, New York, Omaha, Pittsburg, San Francisco, Santa Clara, Seattle, Southfield, Tampa, Temple Terrace, Tysons Corner, WestervilleApply for this job* Permanent* Experienced Professionals* Cybersecurity* ID 556391-en\\_USChoosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more sustainable, more inclusive world.## **Location**This is a remote role based in the US.## **About The Job You're Considering**We are seeking a Senior Security Consultant - Penetration Testing & DevSecOps with 5-8 years of cybersecurity experience and strong expertise in application penetration testing, offensive security, DevSecOps, SSDLC, and vulnerability management. The role focuses on conducting security assessments across applications, APIs, cloud environments, and CI/CD pipelines, while collaborating with development and engineering teams to embed security throughout the software development lifecycle. The ideal candidate combines strong technical skills, a proactive security mindset, and the ability to communicate risks effectively to both technical and business stakeholders.## **Your Role****Penetration Testing & Offensive Security*** Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure.* Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities following industry-standard methodologies such as OWASP, PTES, NIST, and MITRE ATT&CK.* Identify security vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations.* Execute security assessments against modern architectures including microservices, containers, Kubernetes, and cloud-native applications.* Develop proof-of-concepts to demonstrate security weaknesses and attack paths.* Prepare detailed technical reports and executive summaries for customers and stakeholders.**DevSecOps & Secure SDLC*** Integrate security controls and testing into CI/CD pipelines.* Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions.* Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices.* Participate in security architecture reviews, threat modeling exercises, and secure design assessments.* Automate security testing and compliance validation within DevOps toolchains.* Develop security guardrails and policy-as-code capabilities to improve software security posture.**Vulnerability Management & Security Engineering*** Perform vulnerability triage, risk prioritization, and remediation tracking.* Support continuous security monitoring and risk assessment activities.* Analyze emerging threats, attack techniques, and security trends to improve testing methodologies.* Assist in development of security standards, procedures, and best practices.* Work with engineering, cloud, and infrastructure teams to enhance organizational security posture.**Stakeholder Engagement*** Present findings and recommendations to developers, architects, engineering teams, and leadership.* Provide security consulting throughout the software development lifecycle.## **Your Skills And Experience****Education*** Bachelor's degree in Computer Science, Information Security, Engineering, or a related field.**Experience*** 5-8 years of hands-on cybersecurity experience.* Minimum 3+ years of experience conducting application and API penetration testing.* Experience implementing or supporting DevSecOps initiatives within CI/CD environments.**Technical Skills*** Strong understanding of:+ Web Application Security+ API Security+ Secure SDLC+ OWASP Top 10+ OWASP API Top 10+ MITRE ATT&CK+ Threat Modeling+ Vulnerability Management* Hands-on experience with:+ Burp Suite Professional+ Nmap+ Nessus / Qualys / Tenable+ Metasploit+ Kali Linux+ Checkmarx+ Veracode+ Snyk+ SonarQube+ GitHub Actions / Azure DevOps / Jenkins**Desired Qualifications****Certifications :**One or more of the following certifications:* OSCP (Preferred)* CRTO* PNPT* CEH* GWAPT* GPEN* CISSP* CCSP* Azure Security Engineer Associate* AWS Security Specialty**Additional Skills :*** Experience with container security (Docker, Kubernetes).* Experience conducting cloud penetration testing.* Understanding of Infrastructure as Code (Terraform, CloudFormation).* Familiarity with Red Team methodologies and adversary simulation.* Experience with AI/LLM security testing is a plus.* Exposure to Zero Trust Architecture and Secure-by-Design principles.* Excellent communication, consulting, and stakeholder management skills.The base compensation range for this role in the posted location is: **$70,176- $170,040.**Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.It is not typical for candidates to be hired at or near the top of the posted compensation range.In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.**Capgemini offers a comprehensive, non-negotiable benefits package to all regular, full-time employees.** In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include: * Paid time off based on employee grade (A-F), defined by policy: Vacation: 12-25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave* Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)* Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)* Life and disability insurance* Employee assistance programs* Other benefits as provided by local policy and eligibility**Important Notice:** Compensation (including bonuses, commissions, or other forms of incentive pay) is not considered earned, vested, or payable until it becomes due under the terms of applicable plans or agreements and is subject to Capgemini’s discretion, consistent with applicable laws. The Company reserves the right to amend or withdraw compensation programs at any time, within the limits of applicable legislation.**Disclaimers**Capgemini is an Equal Opportunity Employer encouraging inclusion in the workplace. Capgemini also participates in the Partnership Accreditation in Indigenous Relations (PAIR) program which supports meaningful engagement with Indigenous communities across Canada by promoting fairness, accessibility, inclusion and respect. We value the rich cultural heritage and contributions of Indigenous Peoples and actively work to create a welcoming and respectful environment. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodation does not pose an undue hardship. Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.Click the following link for more information on your rights as an Applicant in the United States. http://www.capgemini.com/resources/equal-employment-opportunity-is-the-law
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Sales / Solutions Engineer
Cybersecurity Sales / Solutions Engineer

Capgemini • Northern (KY), New York (NY)

Hybrid
USD 94,000 - 215,000
Health benefits
401(k) plan
Competitive compensation
Senior Consultant (Test Consultant)
Senior Consultant (Test Consultant)

Capgemini • Chicago (IL), Northern (KY)

On-site
USD 88,000 - 178,000
Paid time off
Medical, dental, and vision coverage
Retirement savings plans
+2
DevOps Lead
DevOps Lead

Capgemini • New York (NY), Northern (KY)

On-site
USD 119,000 - 160,000
Senior Manager (Technical Lead)
Senior Manager (Technical Lead)

Capgemini • Chicago (IL), Northern (KY)

On-site
USD 203,000 - 231,000
Cybersecurity Sales / Solutions Engineer
Cybersecurity Sales / Solutions Engineer

Capgemini • Guaynabo (PR)

On-site
USD 94,000 - 215,000
Paid time off
Health/dental/vision insurance
401(k) retirement plan
SDET (Software Development Engineer in Test)
SDET (Software Development Engineer in Test)

Capgemini • Dallas (TX), Northern (KY)

On-site
USD 70,000 - 94,000
Paid time off
Medical, dental, vision
401(k) plan
Software Engineer in Test
Software Engineer in Test

Capgemini • New York (NY), Northern (KY)

Hybrid
USD 85,000 - 97,000
C&CA: Associate Application Consultant
C&CA: Associate Application Consultant

Capgemini • New York (NY), Northern (KY)

Hybrid
USD 49,000 - 93,000
Paid time off
Medical, dental, and vision coverage
Retirement savings plans
+1
Oil & Gas Industry- Senior Business Advisor
Oil & Gas Industry- Senior Business Advisor

Capgemini • Houston (TX), Northern (KY)

Hybrid
USD 82,000 - 234,000
Test Automation Engineer
Test Automation Engineer

Capgemini • Smithfield (RI), Northern (KY)

Hybrid
USD 65,000 - 72,000
Health benefits
401(k) retirement plan