Senior Security Engineer / Senior Penetration Tester

Strategic Resources International Inc

San Jose (CA)

On-site

USD 150,000 - 190,000

Full time

29 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Strategic Resources International Inc. seeks a Senior Infrastructure Penetration Tester to join our Offensive Security team.

The candidate will perform advanced infrastructure assessments across cloud and on-prem environments, including identity systems, networks, and internet-facing assets. Ideal candidates have 6+ years of hands-on penetration testing experience in large-scale tech environments, can develop attack paths, and communicate findings to engineers and senior leadership.

Qualifications

  • 6+ years of hands-on penetration testing in large-scale environments.
  • Experience with enterprise infrastructure, cloud platforms, identity systems, networks.
  • Ability to communicate findings to engineers and leadership.
  • W2 employment and onsite from Day 1 in San Jose, CA.

Responsibilities

  • Plan and execute internal and external infrastructure penetration tests across large enterprise environments.
  • Assess Windows, Linux, Unix, network, virtualization, container, and hybrid infrastructure.
  • Conduct network, host, service, and application-layer security testing.
  • Identify vulnerabilities and demonstrate realistic attack paths and business impact.
  • Perform authenticated and unauthenticated penetration testing.
  • Conduct lateral movement, privilege escalation, credential-access, and persistence assessments within authorized environments.
  • Evaluate segmentation and security controls between corporate, production, R&D, cloud, and restricted environments.
  • Assess security of common enterprise services including DNS, DHCP, VPN, SSH, HTTP/S, LDAP, Kerberos, SMB, RDP, databases, proxies, and authentication infrastructure.
  • Present findings to engineering teams, security leadership, and executive stakeholders; validate remediation and perform retesting.

Skills

Penetration testing
Offensive security
Infrastructure security
Networking
Windows security
Linux security
Adversary simulation

Tools

AWS
Azure
Google Cloud Platform
Kubernetes
Docker
CI/CD tooling

Job description

Experience: 8+ years Function: Cybersecurity / Offensive Security W2


About The Role

We are seeking an experienced Senior Infrastructure Penetration Tester to join our Offensive Security organization. The ideal candidate will have approximately 6+ years of hands-on penetration testing experience in large-scale technology environments and a strong understanding of enterprise infrastructure, cloud platforms, identity systems, networks, and modern attack techniques.


Infrastructure Penetration tester

Experience: 8+ years Location :Sanjose CA (Onsite from Day 1) Level: Senior Security Engineer / Senior Penetration Tester Function: Cybersecurity / Offensive Security W2


About The Role

We are seeking an experienced Senior Infrastructure Penetration Tester to join our Offensive Security organization. The ideal candidate will have approximately 6+ years of hands-on penetration testing experience in large-scale technology environments and a strong understanding of enterprise infrastructure, cloud platforms, identity systems, networks, and modern attack techniques. In this role, you will conduct sophisticated security assessments across corporate infrastructure, cloud environments, data centers, production services, identity platforms, and internet-facing assets. You will work closely with infrastructure, cloud, engineering, security operations, and incident response teams to identify exploitable weaknesses and drive measurable risk reduction. The successful candidate should be comfortable operating independently, developing attack paths, chaining vulnerabilities, and communicating technical findings to both engineers and senior leadership.


Key Responsibilities

Infrastructure Penetration Testing


  • Plan and execute internal and external infrastructure penetration tests across large enterprise environments.

  • Assess Windows, Linux, Unix, network, virtualization, container, and hybrid infrastructure.

  • Conduct network, host, service, and application-layer security testing.

  • Identify vulnerabilities and demonstrate realistic attack paths and business impact.

  • Perform authenticated and unauthenticated penetration testing.

  • Conduct lateral movement, privilege escalation, credential-access, and persistence assessments within authorized environments.

  • Evaluate segmentation and security controls between corporate, production, R&D, cloud, and restricted environments.

  • Assess security of common enterprise services including DNS, DHCP, VPN, SSH, HTTP/S, LDAP, Kerberos, SMB, RDP, databases, proxies, and authentication infrastructure.


Active Directory & Identity Security


  • Perform penetration testing of Active Directory and enterprise identity environments.

  • Assess Kerberos, NTLM, LDAP, Group Policy, trusts, privileged accounts, service accounts, and delegation configurations.

  • Identify paths to domain administrator and other high-value privileges.

  • Evaluate identity federation, SSO, MFA, privileged access management, and service identities.

  • Assess identity attack paths across hybrid environments such as on-premises Active Directory and cloud identity providers.


Cloud & Modern Infrastructure


  • Conduct penetration testing across AWS, Azure, and/or Google Cloud Platform environments.

  • Assess cloud IAM, roles, policies, storage, compute, networking, APIs, secrets, and management interfaces.

  • Test cloud-to-corporate and cloud-to-production attack paths.

  • Assess Kubernetes, containers, Docker, service meshes, and cloud-native infrastructure.

  • Identify privilege-escalation and lateral-movement opportunities across cloud environments.

  • Evaluate infrastructure-as-code and configuration risks where applicable.


External Attack Surface


  • Perform continuous and point-in-time assessments of internet-facing infrastructure.

  • Identify exposed services, misconfigurations, vulnerabilities, weak authentication, and attack paths.

  • Conduct reconnaissance and attack-surface analysis using both commercial and open-source technologies.

  • Validate findings from vulnerability scanners through manual exploitation and controlled testing.

  • Assess perimeter security, WAFs, firewalls, VPNs, reverse proxies, CDN infrastructure, and other defensive controls.


Adversary Simulation


  • Develop realistic attack scenarios based on current threat actor techniques.

  • Chain multiple weaknesses to demonstrate realistic compromise scenarios.

  • Collaborate with Red Team, Purple Team, Detection Engineering, and Security Operations teams.

  • Develop proof-of-concept exploits and attack automation where appropriate.

  • Validate preventive and detective security controls.

  • Translate offensive findings into actionable defensive improvements.


Automation & Tool Development


  • Develop scripts and tooling to improve penetration-testing efficiency and scalability.

  • Automate reconnaissance, vulnerability validation, attack-path discovery, evidence collection, and reporting.

  • Integrate offensive-security tooling into enterprise security workflows.

  • Leverage Python, PowerShell, Bash, and other scripting/programming languages.

  • Evaluate and responsibly use AI-assisted security testing tools while maintaining human validation and authorization controls.


Reporting & Risk Management


  • Produce high-quality penetration-testing reports that clearly communicate:

  • Vulnerability

  • Attack path

  • Exploitability

  • Business impact

  • Affected assets

  • Evidence

  • Remediation recommendations


Present findings to engineering teams, security leadership, and executive stakeholders. Work with infrastructure owners to validate remediation and perform retesting. Track recurring weaknesses and identify systemic security issues. Help establish security metrics such as remediation rates, exploitability, attack-path reduction, and risk exposure.


Required Qualifications


  • 6+ years of professional experience in penetration testing, offensive security, infrastructure security, or closely related cybersecurity disciplines.

  • Strong hands-on experience conducting enterprise infrastructure penetration tests.

  • Deep understanding of TCP/IP networking and common enterprise protocols.

  • Strong Windows and Linux security knowledge.

  • Demonstrated experience with Active Directory and enterprise identity systems.

  • Experience with cloud security and at least one major cloud platform: AWS, Azure, or Google Cloud Platform.

  • Experience identifying and exploiting common infrastructure vulnerabilities.

  • Strong understanding of authentication, authorization, privilege escalation, lateral movement, and defense evasion concepts.

  • Experience with vulnerability scanners and manual validation.

  • Strong scripting skills in Python, PowerShell, Bash, or similar languages.

  • Ability to independently scope, execute, document, and communicate penetration-testing engagements.

  • Strong written and verbal communication skills.

  • Ability to work effectively with infrastructure and engineering teams in a large technology organization.

  • Demonstrated ability to operate within strict rules of engagement and responsible-disclosure requirements.


Preferred Qualifications


  • Experience working in a large-scale Big Tech or hyperscale technology environment.

  • Experience with Kubernetes, Docker, containers, service meshes, and cloud-native architectures.

  • Experience testing CI/CD infrastructure, DevOps platforms, and infrastructure-as-code.

  • Experience with security testing of APIs and microservices.

  • Experience with red teaming or adversary simulation.

  • Experience developing custom offensive-security tooling.

  • Experience with attack-path analysis and identity-centric security assessments.

  • Experience assessing zero-trust architectures.

  • Experience with security testing of SaaS and internally developed enterprise platforms.

  • Understanding of software supply-chain security and CI/CD attack paths.

  • Experience working with bug bounty or vulnerability disclosure programs.

  • Experience integrating penetration testing into enterprise security programs.


Technical Skills

Operating Systems



  • Windows / Windows Server

  • Linux / Unix

  • macOS


Networking



  • TCP/IP

  • DNS

  • HTTP/S

  • SSH

  • VPN

  • SMB

  • RDP

  • LDAP

  • Kerberos

  • TLS

  • Firewalls / WAF / Proxies


Identity



  • Active Directory

  • Entra ID / Azure AD

  • LDAP

  • Kerberos

  • SAML

  • OAuth/OIDC

  • MFA

  • PAM


Cloud



  • AWS

  • Azure

  • Google Cloud Platform

  • IAM

  • VPC/VNet

  • Cloud storage

  • Containers

  • Kubernetes


Security Tools


Candidates should be able to understand and adapt tools rather than simply execute automated scanners.


Core Competencies


  • Offensive Security Mindset

  • Enterprise Infrastructure Expertise

  • Identity & Active Directory Security

  • Cloud Security

  • Attack-Path Analysis

  • Adversary Simulation

  • Automation & Tool Development

  • Risk-Based Thinking

  • Strong Technical Communication

  • Engineering Partnership


Role Profile

This is a hands-on senior individual contributor role. The ideal candidate is not simply a vulnerability scanner or compliance tester they are an experienced security engineer who can think like an attacker, understand complex enterprise infrastructure, demonstrate realistic compromise paths, and work with engineering teams to eliminate systemic weaknesses.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Penetration Tester / Security Assessor — Cyber Threat Intelligence
Penetration Tester / Security Assessor — Cyber Threat Intelligence

Dale Workforce Solutions • Columbia (SC)

On-site
USD 90,000 - 150,000
Senior Software Security Engineer / DevSecOps
Senior Software Security Engineer / DevSecOps

GTN Technical Staffing • Dallas (TX)

On-site
USD 140,000 - 195,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Penetration Tester
Penetration Tester

CGVantage • United States

On-site
USD 110,000 - 170,000
Penetration Tester
Penetration Tester

BrothersTech • United States

On-site
USD 95,000 - 150,000
Penetration Tester
Penetration Tester

Altus Consulting Corporation • Herndon (VA)

On-site
USD 100,000 - 150,000
Competitive compensation and benefits package
Opportunities for professional development
Collaborative work environment
+1
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000