Senior Associate, Offensive Security

Jobtailor

New York (NY)

Hybrid

USD 120,000 - 160,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Pfizer is seeking an experienced Offensive Security professional in New York to perform penetration testing across on-premises, cloud, and hybrid environments. You will support red team and purple team engagements, document weaknesses with remediation guidance, and help translate findings into actionable improvements for detection, engineering, and remediation teams.

The role requires hands-on offensive security experience, knowledge of attack techniques across identities, endpoints, networks,

Qualifications

  • Hands-on experience in offensive security and penetration testing.
  • Experience performing security assessments and reporting findings.
  • Knowledge of attack techniques across identity, endpoints, networks, and cloud.
  • Ability to document findings and communicate risk to technical stakeholders.

Responsibilities

  • Conduct offensive security testing across on-premises, cloud, and hybrid environments.
  • Support red team and purple team engagements by executing test plans, collecting evidence, and evaluating defensive control effectiveness.
  • Identify, validate, and document security weaknesses with technical details, proof-of-concept evidence, and remediation recommendations.
  • Translate offensive findings into actionable improvements for detection, engineering, and remediation teams.
  • Map observed techniques to common attacker behaviors and identify realistic attack paths.
  • Maintain accurate, complete, and compliant offensive security reports and deliverables.
  • Improve offensive security tooling, automation, repeatable testing methods, and playbooks.
  • Collaborate with detection, incident response, vulnerability management, infrastructure, and cloud teams to coordinate testing and minimize disruption.
  • Escalate complex technical issues, high-risk findings, and unexpected conditions.
  • Report to the Sr. Manager, Offensive Security.

Skills

Offensive security
Penetration testing
Python
PowerShell
Bash
Vulnerability research
Security engineering
Technical documentation
Attack techniques
Enterprise security concepts

Education

Bachelor's degree in Information Security, Computer Science, Engineering, or related field

Job description

  • Conduct offensive security testing, including penetration tests and adversary simulation exercises, across on-premises, cloud, and hybrid environments
  • Support red team and purple team engagements by executing test plans, collecting evidence, and evaluating defensive control effectiveness
  • Identify, validate, and document security weaknesses with technical details, proof-of-concept evidence, and remediation recommendations
  • Translate offensive findings into actionable improvements for detection, engineering, and remediation teams
  • Map observed techniques to common attacker behaviors and identify realistic attack paths
  • Maintain accurate, complete, and compliant offensive security reports and deliverables
  • Improve offensive security tooling, automation, repeatable testing methods, and playbooks
  • Collaborate with detection, incident response, vulnerability management, infrastructure, and cloud teams to coordinate testing and minimize disruption
  • Escalate complex technical issues, high-risk findings, and unexpected conditions
  • Report to the Sr. Manager, Offensive Security
Requirements
  • Bachelor's degree in Information Security, Computer Science, Engineering, or related field with at least 2 years of cybersecurity experience; or master's degree with more than 0+ years of experience; or associate's degree with 6 years of experience; or high school diploma or equivalent with 8 years of relevant experience
  • Hands-on experience in offensive security, penetration testing, vulnerability research, or security engineering
  • Practical experience executing penetration tests or security assessments, including reconnaissance, exploitation validation, and reporting
  • Strong understanding of attack techniques and enterprise security concepts across identity, endpoints, networks, and cloud services
  • Ability to document technical findings and communicate risk and remediation guidance to technical stakeholders
  • Working knowledge of at least one scripting/programming language such as Python, PowerShell, or Bash
  • Strong collaboration skills and ability to work in a process-driven, highly regulated environment
  • Must be capable of working through a personal laptop computer or mobile device for extended periods
  • Must be able to work in an assigned Pfizer office 2-3 days per week, or as needed by the business
  • Travel as required by the business, less than 5% domestic and/or international
  • Candidates must be authorized to be employed in the U.S. by any employer
  • Requires permanent work authorization in the United States
  • U.S. work visa sponsorship is not available now or in the future
Core Competencies

Demonstrates expertise in offensive security testing, including penetration testing and vulnerability research, with a strong ability to document findings and communicate risk mitigation strategies. Proficient in collaborating with cross-functional teams to enhance security measures and improve testing methodologies.

Highest-signal resume keywords
  • Offensive Security Testing
  • Penetration Testing
  • Vulnerability Research
  • Scripting/Programming (Python, PowerShell, Bash)
  • Security Assessment Reporting
ATS Optimization Keywords
Hard Skills
  • Offensive Security
  • Penetration Testing
  • Vulnerability Research
  • Security Engineering
  • Exploitation Validation
  • Technical Documentation
  • Attack Techniques
  • Enterprise Security Concepts
  • Cloud Security
  • Risk Communication
Soft Skills
  • Collaboration
  • Process-Driven Work
  • Communication
Industry Keywords
  • Cybersecurity
  • Red Team Engagements
  • Purple Team Engagements
  • Incident Response
  • Vulnerability Management
  • Compliance
  • Technical Stakeholders
  • Security Weaknesses
  • Attack Paths
  • Automation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Associate Principal, Adversarial Red Team
Lead Associate Principal, Adversarial Red Team

Jobtailor • United States

On-site
USD 170,000 - 210,000
Director – Security Remediation Operations
Director – Security Remediation Operations

Jobtailor • Arizona

On-site
USD 180,000 - 280,000
Senior Security Engineer – Penetration Tester
Senior Security Engineer – Penetration Tester

Jobtailor • North Carolina

On-site
USD 120,000 - 190,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Associate Cybersecurity Operations Researcher
Associate Cybersecurity Operations Researcher

Jobtailor • Pennsylvania

On-site
USD 90,000 - 130,000
Lead Security Analyst, Research Computing
Lead Security Analyst, Research Computing

Jobtailor • Knoxville (TN)

On-site
USD 110,000 - 160,000
Senior Penetration Tester
Senior Penetration Tester

Jobtailor • Herndon (VA)

On-site
USD 120,000 - 150,000
Senior Red Team Operator
Senior Red Team Operator

Jobtailor • Huntsville (AL)

On-site
USD 90,000 - 150,000
Senior IS Advisor, Treasury Services Division
Senior IS Advisor, Treasury Services Division

Jobtailor • Town of Montana (WI)

On-site
USD 110,000 - 150,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000