A complete application in a minute — tailored resume and cover letter, ready to send.
Gambit Technologies seeks a Security Engineer to perform penetration testing and vendor security reviews in a hybrid Manhattan environment. You will test apps, assess controls, and verify vendor evidence to drive risk decisions.
You will join a small security team reporting to the CISO, influencing tool selection and security posture across the organization.
Manhattan, hybrid. NYC metro only.
This one is for people who test things.
If you've installed an app and gone looking for what an attacker would find, this role may be for you.
My client is one of the largest private philanthropies in the country, based in Manhattan. The money funds public health, climate, education, government innovation, and the arts, and it moves fast. The security team is small. You report to the CISO directly, you know everyone on the team, and when you tell leadership a tool isn't safe to buy, that's usually where the conversation ends.
Here's what a week looks like. HR wants a new platform that holds employee data. You pull the vendor's SOC 2 and notice the observation window is three months and the scope skips the system that would actually hold the data. Then you spin the tool up and test it yourself, because "we enforce MFA" is a sentence until somebody tries to get around it. You write it up in plain English for HR and Legal, and you're in the room when they decide.
Next week it's a CVE that just dropped. You figure out whether it's actually reachable in this environment or just a scary number. After that maybe it's scoping an outside red team, or tuning DLP rules so they stop firing on every spreadsheet.
You get both halves: the testing, and a real say in what happens with the results. That combination is hard to find.
What they need:
What they'll teach you:
Their tech stack. Splunk, CrowdStrike, Netskope, Qualys, and a few others.
OSCP, GPEN, or GWAPT is a strong signal. People from pentest consultancies or small in-house teams tend to fit well.