Security Engineer, Penetration Testing & Vendor Security

Gambit Technologies

New York (NY)

Hybrid

USD 120,000 - 180,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Gambit Technologies seeks a Security Engineer to perform penetration testing and vendor security reviews in a hybrid Manhattan environment. You will test apps, assess controls, and verify vendor evidence to drive risk decisions.

You will join a small security team reporting to the CISO, influencing tool selection and security posture across the organization.

Qualifications

  • 5+ years in security with hands-on testing experience.
  • Ability to assess vendor evidence for validity and risk.
  • Experience testing applications and auth mechanisms.

Responsibilities

  • Perform hands-on penetration testing of internal and vendor solutions.
  • Review vendor SOC 2 and control evidence for gaps.
  • Communicate findings clearly to HR/Legal and leadership.

Skills

Burp Suite
Kali Linux
Nmap
Manual testing

Education

OSCP/GPEN/GWAPT

Tools

Splunk
CrowdStrike
Netskope
Qualys

Job description

Security Engineer, Penetration Testing & Vendor Security

Manhattan, hybrid. NYC metro only.

This one is for people who test things.

If you've installed an app and gone looking for what an attacker would find, this role may be for you.

My client is one of the largest private philanthropies in the country, based in Manhattan. The money funds public health, climate, education, government innovation, and the arts, and it moves fast. The security team is small. You report to the CISO directly, you know everyone on the team, and when you tell leadership a tool isn't safe to buy, that's usually where the conversation ends.

Here's what a week looks like. HR wants a new platform that holds employee data. You pull the vendor's SOC 2 and notice the observation window is three months and the scope skips the system that would actually hold the data. Then you spin the tool up and test it yourself, because "we enforce MFA" is a sentence until somebody tries to get around it. You write it up in plain English for HR and Legal, and you're in the room when they decide.

Next week it's a CVE that just dropped. You figure out whether it's actually reachable in this environment or just a scary number. After that maybe it's scoping an outside red team, or tuning DLP rules so they stop firing on every spreadsheet.

You get both halves: the testing, and a real say in what happens with the results. That combination is hard to find.

What they need:

  • Hands-on testing. Burp, Kali, Nmap, manual app and auth testing.
  • The judgment to tell what vendor evidence is actually worth.
  • 5+ years in security with real keyboard time.

What they'll teach you:

Their tech stack. Splunk, CrowdStrike, Netskope, Qualys, and a few others.

OSCP, GPEN, or GWAPT is a strong signal. People from pentest consultancies or small in-house teams tend to fit well.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Penetration Tester / Ethical Hacker (Offensive Security)
Penetration Tester / Ethical Hacker (Offensive Security)

Zoho • United States

On-site
USD 83,000 - 165,000
Security VAPT Engineer
Security VAPT Engineer

Salt Digital Recruitment • Chicago (IL)

On-site
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

Ringside Talent • Columbus (OH)

Hybrid
USD 90,000 - 130,000
OSCP/GPEN sponsorship
Hands-on security culture
Penetration Tester
Penetration Tester

Ringside Talent Acquisition Partners • Columbus (OH)

Hybrid
USD 90,000 - 140,000
Penetration Tester
Penetration Tester

CGVantage • United States

On-site
USD 110,000 - 170,000
Offensive Security Consultant
Offensive Security Consultant

Konica Minolta Business Solutions Canada • Kansas City (MO)

On-site
USD 80,000 - 100,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Penetration Tester
Penetration Tester

Saic • Town of Texas (WI)

On-site
USD 120,000 - 160,000
Penetration Tester (Mid+/ Senior)
Penetration Tester (Mid+/ Senior)

UnderDefense Inc. • United States

Hybrid
USD 120,000 - 190,000
Growth opportunities
Competitive salary
Brilliant team
+5