Search 561 Remote GPEN Jobs

561 remote jobs

Cyber Test Engineer

Rome, NY

Job Number R0241786 Cyber Test Engineer The Opportunity Collaborate with a team of creative problem solvers to test and evaluate systems through a Whitebox adversarial approach for the DoD in support of our Air Force clients. Work with systems that are assessed based on NIST 800-53 Risk Management Framework security controls. Focus on filtering capabilities and data flows such as low levels within the architecture of the system including Mandatory Access Controls and Discretionary Access Controls. Build capabilities by learning from others' expertise within our skilled team. You Have Experience with Linux command line including scripting in Ruby Python or Bash and automating basic tasks Experience with networking concepts Experience with virtualization Ability to travel up to 25% of the time Secret clearance HS diploma or GED Ability to obtain a DoD IAT Level II Compliant Security+ CE Certification within 120 days of start date Nice If You Have Experience analyzing and executing test plans and procedures Experience developing or analyzing technical documentation Experience with penetration testing or adversarial emulation Experience with NIST 800-53 security controls Knowledge of cyber threats and how to appropriately harden a system to prevent them Knowledge of vulnerability assessment tools including Kali Linux Wireshark Tripwire Burp Suite and Metasploit TS/SCI clearance Master's degree OSCP CISSP CASP Red Hat CSA or GPEN Certification Clearance Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information Secret clearance is required. Compensation At Booz Allen we celebrate your contributions provide you with opportunities and choices and support your total well-being. Our offerings include health life disability financial and retirement benefits as well as paid leave professional development tuition assistance work-life programs and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors including but not limited to location the individual’s particular combination of education knowledge skills competencies and experience as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $55200.00 to $126000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen and we are committed to the responsible and ethical use of AI tools. However we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided . Work Model Our people-first culture prioritizes the benefits of collaboration whether it occurs in person or virtually. To support engagement and effective communication employees working virtually are generally expected to have their cameras on during meetings. Remote If this position is listed as remote there may still be occasions when you are required to work in person at a Booz Allen or customer facility. Hybrid If this position is listed as hybrid you will be expected to work from a Booz Allen facility frequently in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. Onsite If this position is listed as onsite work will primarily be performed at a Booz Allen office or customer facility where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability status as a protected veteran or any other status protected by applicable federal state local or international law.

Virtual CISO & Cybersecurity Practice Lead

Remote

WHO WE ARE The PR industry hasn't really changed in fifty years. Relationships lunches luck and a clip report at the end of the month. Interdependence is rebuilding it from the ground up. Interviewed our proprietary platform analyzes 300000+ stories every day across a network of 250000 journalists. We turn earned media into something measurable repeatable and worth paying for — and apply the same data and discipline across paid social content and brand. Integrated marketing run by one team on one system accountable to one result. Forbes named us one of America's Best PR Agencies. Our 100+ person team works with brands CMOs founders and entrepreneurs across consumer healthcare tech B2B travel and entertainment. We move fast. The best argument wins. We hire for sharp thinking real craft and ownership from day one. If you want comfortable this isn't the place. If you want to win build with us. THE ROLE You will serve as the senior cybersecurity practitioner and virtual CISO to a growing portfolio of mid-market clients (typically $25M–$150M in revenue 100–1000 employees). You will own the full client lifecycle from initial security risk assessments through ongoing advisory compliance management and incident response coordination. KEY RESPONSIBILITIES Serve as the outsourced CISO for 8–12 clients providing executive-level security leadership on a fractional basis Conduct security risk assessments gap analyses and penetration testing oversight for prospective and current clients Develop and maintain security programs policies and incident response plans tailored to each client's risk profile and regulatory environment Manage compliance frameworks including SOC 2 HIPAA PCI-DSS CCPA NIST CSF and CMMC Present security posture risk exposure and remediation roadmaps to boards of directors C-suites and audit committees in clear business-oriented language Oversee and leverage AI-driven security tooling for vulnerability scanning log analysis threat detection and compliance evidence collection Quarterback incident response when clients face active threats or breaches coordinating forensics legal communications and remediation Collaborate with RMC's reputation management team to deliver integrated crisis response when security events create reputational exposure Participate in business development — joining sales conversations scoping engagements and helping close new cybersecurity retainers Recruit manage and mentor junior analysts as the practice scales Build standardized methodologies reporting templates and delivery playbooks that allow the practice to scale without sacrificing quality QUALIFICATIONS 7-10+ years of hands-on cybersecurity experience spanning at least two of the following penetration testing incident response security architecture GRC (governance risk and compliance) 3+ years operating at the CISO Director of Security or senior consulting level you've sat in the room with boards and translated technical risk into business impact CISSP certification (active and in good standing) Deep working knowledge of SOC 2 HIPAA NIST CSF and at least one additional framework (PCI-DSS ISO 27001 CMMC CCPA) Experience building or significantly expanding a security program from early stages not just maintaining one someone else built Ability to manage multiple client engagements simultaneously without quality degradation Comfortable participating in sales and business development conversations — you understand that your credibility is what closes deals NICE TO HAVE CMMC Registered Practitioner (RP) or Certified CMMC Assessor (CCA) — the Southern California defense industrial base is a priority vertical Additional certifications CISM CRISC OSCP GPEN or SANS GIAC credentials Experience running a cybersecurity consulting practice MSSP or vCISO firm — either as founder or practice lead Background in incident response or digital forensics Familiarity with AI-driven security platforms and willingness to integrate emerging AI tooling into service delivery Experience with cyber insurance underwriting requirements and risk assessment frameworks Existing professional network in the Southern California cybersecurity community WHAT WILL SET YOU APART You've built something before a practice a team a firm and you want to do it again with resources and infrastructure behind you You can explain a zero-day exploit to a board member and a budget justification to a CFO in the same meeting You're not just a technician who moved into management you genuinely enjoy the client relationship and advisory aspects of the work You see AI as a force multiplier for your expertise not a threat to it WHY THIS ROLE You'll have an existing client base to cross-sell into from day one. You'll have AI-powered tooling that handles the repetitive analytical work so you can focus on the high-value advisory that clients actually pay for. And you'll have a leadership team that understands professional services client management and scaling consulting practices. because that's what we've done for over two decades. If you want to build a cybersecurity practice with the autonomy of a founder and the support system of an established firm this is it. COMPENSATION & STRUCTURE Base salary $200000 – $300000 depending on experience and credentials Performance bonus Up to 25% of base tied to client acquisition retention and practice revenue targets Revenue participation Structured incentive on new business you source and close designed to reward you as a practice builder not just a practitioner WHY YOU'LL LOVE WORKING AT INTERDEPENDENCE 100% Remote Forever - Work from anywhere in the U.S. while enjoying the flexibility of a fully remote workplace. Skip the commute create a workspace that works for you and collaborate with teammates across the country all without sacrificing connection or career growth. Comprehensive Health Benefits - Choose from three Anthem Blue Cross PPO medical plans plus dental and vision coverage to support your health and well-being. Retirement Savings - Save for the future with our 401(k) program including a company match that is increasing to 3% by 2027 Work-Life Balance - Enjoy paid vacation sick time 11 company holidays a floating holiday and Summer Fridays to recharge and spend more time doing what you love. Paid Maternity Leave - We support growing families with paid maternity leave giving new moms dedicated time to recover bond with their baby and return to work with confidence. Career Growth - As one of the nation's fastest-growing PR and strategic communications firms we're committed to helping ambitious people grow. Take on meaningful challenges develop new skills lead from every level and build a career with real impact. Supportive Collaborative Culture - We set high standards celebrate big wins and work together to achieve exceptional results. You'll join a team that's collaborative entrepreneurial and committed to helping one another succeed.

Senior Vulnerability Management & Incident Response Analyst

Bengaluru, Karnataka, India

Where you’ll work Bangalore KA IN IT & Tech Ops at GoTo GoTo’s IT & Tech Ops team enables a remote-first high-performance workplace—powered by state-of-the-art AI technology. We’re dedicated to delivering seamless digital experiences that boost productivity and collaboration for every employee worldwide. By harnessing AI we automate routine tasks proactively identify solutions and open new doors for global teamwork and problem-solving. Join our tech innovators and help reimagine the future of work for our teams and customers. About Security At GoTo At GoTo security is at the core of empowering businesses in a 'work anywhere secure everywhere' world. By embedding security and privacy into our processes by design and by default we prioritize safeguarding business assets customer data and employee information without compromising usability. In a Security Operations role our focus is on enabling rapid vulnerability identification effective remediation responding to incidents and maintaining organizational resilience in an ever-evolving threat landscape. Your Day to Day As a Senior Vulnerability Operations and Incident Response Analyst your job responsibilities would be Own the end-to-end vulnerability management lifecycle - discovery risk-based prioritization remediation tracking and verification across cloud endpoint network and application environments. Assist in building and maintaining automation for vulnerability scanning ticketing SLA tracking and reporting to reduce manual effort and accelerate remediation velocity. Lead the response to zero-day and critical vulnerabilities coordinating rapid impact assessment compensating controls and cross-team remediation under time pressure. Manage third-party and supply chain vulnerability risk including SBOM analysis and coordinated disclosure handling. Support Security Operations Center (SOC) monitoring and incident response investigations as a secondary responsibility assisting with triage containment support and documentation. Actively participate in Purple Team exercises with SOC and Offensive Security teams to validate that identified vulnerabilities are properly detected and remediated. Champion the adoption of AI and automation within the vulnerability management and Incident Response program to improve scanning coverage prioritization accuracy Incident handling and analyst productivity. Provide structured feedback and mentorship to junior analysts on vulnerability management and Incident Response best practices. Stay current with emerging vulnerabilities exploit trends and threat intelligence translating findings into actionable prioritization and remediation guidance. What We're Looking For As a Senior Vulnerability Operations and Incident Response Analyst your background will look like 5+ years of hands-on experience in vulnerability management security operations or a similar cybersecurity role with a proven track record owning a VM program end-to-end. Demonstrated experience automating vulnerability management workflows and strong understanding of risk-based prioritization frameworks (e.g. CVSS EPSS) applied across cloud on-prem and application environments. Experience handling zero-day vulnerability response and third-party/supply chain vulnerability risk including SBOM analysis and vendor security assessments. Beginner-to-intermediate working knowledge of SOC operations and incident response processes with the ability to support IR investigations when needed. Effective communication skills with the ability to document vulnerability risks and translate technical findings for diverse audiences. Additional Qualifications Experience with CI/CD pipeline security scanning (SAST DAST SCA) and secure software supply chain practices Hands-on exposure to SOAR platforms or custom automation frameworks Relevant certifications (e.g. GEVA GCFR GCFA GPEN AWS Security Specialty CompTIA Security+) What We Offer At GoTo we care about helping our people succeed at work and feel supported in life. Our employee benefits and programs are designed to support your well-being growth and sense of belonging. Here's what you can expect as part of our team Comprehensive health benefits Generous paid time off including paid holidays volunteer days quarterly self-care days and company-designated no-meeting days Tuition reimbursement and access to instructor-led and on-demand learning and development programs The Thrive Global Wellness Program a confidential Employee Assistance Program (EAP) a wellness app and one-on-one wellness coaching Employee-led communities and programs including Employee Resource Groups (ERGs) GoTo Gives and charitable matching We work hard to create an environment where everyone feels welcome respected and able to contribute. Building a culture of belonging isn't just something we talk about - it's part of how we work every day. Specific benefits and offerings may vary by country in line with local regulations and market practices. At GoTo you’ll find the flexibility resources and support you need to thrive—at work at home and everywhere in between. You’ll work towards a shared goal with an open-minded cohesive team that’s greater than the sum of its parts. We’re committed to creating an inclusive space for everyone because we know unique perspectives make us a stronger company and community. Join us and be part of a company that invests in your future where together we’ll Be Real Think Big Move Fast Keep Growing and stay Customer Obsessed. Learn more.

Senior Offensive Security Engineer - Pentester

Chicago, IL

Job Description At Bank of America we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients teammates communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace attracting and developing exceptional talent supporting our teammates’ physical emotional and financial wellness recognizing and rewarding performance and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America you can build a successful career with opportunities to learn grow and make an impact. Join us! Job Description Are you passionate about cybersecurity and looking to work with some of the best information security professionals in the world in challenging environments? Bank of America is hiring top talent to join our team. You bring your talent and passion and we’ll provide you with an opportunity to shine and grow. The Cyber Security Assurance Division is looking for a Senior Full Stack Pentester to join a team of world-class offensive security professionals. In this role you will diligently hunt for high-risk vulnerabilities across the bank’s global technology environment. Understanding security policy and compliance is important but in this role your focus is to identify exploitable vulnerabilities in critical systems ones that can bring about that “nightmare scenario.” This is a highly-technical role that requires broad technical knowledge a deep understanding of threats and a hacker mentality. You will lead and participate in collaborative technical assessments that leverage a wide range of penetration testing techniques (reconnaissance weaponization delivery exploitation) to identify and prove the concept of high-risk vulnerabilities across a variety of technologies. Your strong problem-solving skills practical demonstration of technical competency and lateral thinking will contribute to our team-first culture of collaboration and impactful findings. This senior technical role is responsible for leading and performing assessments of the bank's technologies applications and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research understanding the bank's security policy working with appropriate partners to complete assessments identifying misconfigurations and vulnerabilities to achieve security impact and reporting on the associated risk. These individuals partner closely with security partners CIO clients and multiple lines of business. You will coordinate with senior leadership on development projects share your knowledge and experience by mentoring junior engineers and assist with monitoring and response functions so those teams can practice and improve their capability to respond to a realistic threat actor. Required Skills Minimum of 5+ years of professional offensive security experience Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear precise terms to technical and non-technical audiences. Must be very proficient with the common tools associated with penetration testing (Burp Suite Metasploit nmap etc.). Must have a solid understanding of voice and data networks major operating systems active directory their associated peripherals and a strong desire to learn new technologies and skill sets. Must demonstrate knowledge of tactics techniques and procedures associated with malicious activity an understanding of industry classifications and frameworks and the ability to chain vulnerabilities in the advanced exploitation of systems. Must be proficient in report delivery and technical documentation of vulnerabilities. Must be able to effectively code in a programming or scripting language (Python Java C etc.) Desirable Skills Certifications OSCP GPEN GXPN OSED OSEP OSWE OSCE GWAPT Ability to work remotely if/when necessary Previous experience working in the financial industry Experience with hardware hacking embedded systems analysis and IoT hacking This job will be open and accepting applications for a minimum of seven days from the date it was posted. Shift 1st shift (United States of America) Hours Per Week 40

Senior Red Team Operator

Wrocław, Dolnośląskie, Poland

Red Team Operator Location Wrocław / Katowice - 2 days in office / 3 days remote Let us introduce you the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY. Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services as well as detect and quickly respond to security events as they happen. Together the efforts of our dedicated team helps protect the EY brand and build client trust. Within Information Security we blend risk strategy digital identity cyber defense application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking security-focused individuals dedicated to supporting protecting and enabling the business through innovative secure solutions that provide speed to market and business value. The opportunity As a Red Team Operator within the Attack Surface Management team you will emulate advanced threat actors through offensive security testing and adversary emulation. You will identify vulnerabilities demonstrate business and operational risks and provide actionable recommendations to improve defenses. Your Key Responsibilities Plan execute and lead red team operations and adversary emulation including reconnaissance initial access execution persistence lateral movement exfiltration and impact. Conduct advanced penetration testing across environments external/internal networks web/cloud applications APIs Active Directory identity systems and hybrid/cloud infrastructures. Perform social engineering (e.g. phishing) as part of integrated engagements. Identify validate exploit and chain vulnerabilities to demonstrate realistic attack paths and business risks. Collaborate in Purple Team exercises with defensive teams to improve detection response and resilience. Produce high-quality deliverables detailed technical reports executive summaries risk assessments and remediation recommendations. Mentor junior team members provide technical oversight and contribute to methodology improvements and tooling (e.g. custom exploits automation scripts). Stay current with emerging threats TTPs exploits and defensive countermeasures through research conferences and self-development. Skills And Attributes For Success Deep expertise in offensive security tools and frameworks (e.g. Metasploit Cobalt Strike / custom C2 Empire BloodHound Nmap Burp Suite and others).Demonstrated ability to thinking critically Strong knowledge of networking operating systems (Windows/Linux) Active Directory cloud platforms (AWS/Azure/GCP) web app security and common protocols. Proficiency in scripting/programming (Python PowerShell Bash etc.) for automation and custom tooling. Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders. Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence. Independently research and stay knowledgeable of Threat Actor TTP’s and how they may be leveraged. Excellent analytical problem-solving and technical writing skills. Strong teamwork independence and communication skills. To qualify for the role you must have 6-8 years of hands-on experience in penetration testing red teaming or offensive security. Demonstrated experience executing red team or advanced penetration testing engagements. Relevant certifications including OSCP CPTS (or equivalents such as GPEN CRTO OSEP OSCE). Ability to work effectively in a fully remote environment. Ideally you’ll also have Experience with threat intelligence-driven adversary emulation (e.g. MITRE ATT&CK framework TIBER-EU). Prior consulting or client-facing experience (where applicable). Knowledge of purple teaming security operations (SOC) incident response and detection engineering. Creation of or contributions to open-source tools or projects CTF participation or public research/blogging. What We Look For We are looking for a senior operator that can operate autonomously and bring new strategic approaches to discovering and evaluating the firm’s attack surface to improve the overall security posture. We are seeking a seasoned operator to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What We Offer EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina Hungary India the Philippines Poland Sri Lanka Mexico Spain and the United Kingdom – and with teams from all EY service lines geographies and sectors playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people learning skills and insights that will stay with you throughout your career. Continuous learning You’ll develop the mindset and skills to navigate whatever comes next. Success as defined by you We’ll provide the tools and flexibility so you can make a meaningful impact your way. Transformative leadership We’ll give you the insights coaching and confidence to be the leader the world needs. Diverse and inclusive culture You’ll be embraced for who you are and empowered to use your voice to help others find theirs. About EY EY Building a better working world EY exists to build a better working world helping to create long-term value for clients people and society and build trust in the capital markets. Enabled by data and technology diverse EY teams in over 150 countries provide trust through assurance and help clients grow transform and operate. Working across assurance consulting law strategy tax and transactions EY teams ask better questions to find new answers for the complex issues facing our world today. If you can demonstrate that you meet the criteria above please contact us as soon as possible. The Exceptional EY Experience. It’s Yours To Build. In compliance with the requirements of the Whistleblower Protection Act our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions . Any misconduct should be reported through the EY Ethics Hotline.

Senior Red Team Operator

Katowice, Śląskie, Poland

Red Team Operator Location Wrocław / Katowice - 2 days in office / 3 days remote Let us introduce you the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY. Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services as well as detect and quickly respond to security events as they happen. Together the efforts of our dedicated team helps protect the EY brand and build client trust. Within Information Security we blend risk strategy digital identity cyber defense application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking security-focused individuals dedicated to supporting protecting and enabling the business through innovative secure solutions that provide speed to market and business value. The opportunity As a Red Team Operator within the Attack Surface Management team you will emulate advanced threat actors through offensive security testing and adversary emulation. You will identify vulnerabilities demonstrate business and operational risks and provide actionable recommendations to improve defenses. Your Key Responsibilities Plan execute and lead red team operations and adversary emulation including reconnaissance initial access execution persistence lateral movement exfiltration and impact. Conduct advanced penetration testing across environments external/internal networks web/cloud applications APIs Active Directory identity systems and hybrid/cloud infrastructures. Perform social engineering (e.g. phishing) as part of integrated engagements. Identify validate exploit and chain vulnerabilities to demonstrate realistic attack paths and business risks. Collaborate in Purple Team exercises with defensive teams to improve detection response and resilience. Produce high-quality deliverables detailed technical reports executive summaries risk assessments and remediation recommendations. Mentor junior team members provide technical oversight and contribute to methodology improvements and tooling (e.g. custom exploits automation scripts). Stay current with emerging threats TTPs exploits and defensive countermeasures through research conferences and self-development. Skills And Attributes For Success Deep expertise in offensive security tools and frameworks (e.g. Metasploit Cobalt Strike / custom C2 Empire BloodHound Nmap Burp Suite and others).Demonstrated ability to thinking critically Strong knowledge of networking operating systems (Windows/Linux) Active Directory cloud platforms (AWS/Azure/GCP) web app security and common protocols. Proficiency in scripting/programming (Python PowerShell Bash etc.) for automation and custom tooling. Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders. Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence. Independently research and stay knowledgeable of Threat Actor TTP’s and how they may be leveraged. Excellent analytical problem-solving and technical writing skills. Strong teamwork independence and communication skills. To qualify for the role you must have 6-8 years of hands-on experience in penetration testing red teaming or offensive security. Demonstrated experience executing red team or advanced penetration testing engagements. Relevant certifications including OSCP CPTS (or equivalents such as GPEN CRTO OSEP OSCE). Ability to work effectively in a fully remote environment. Ideally you’ll also have Experience with threat intelligence-driven adversary emulation (e.g. MITRE ATT&CK framework TIBER-EU). Prior consulting or client-facing experience (where applicable). Knowledge of purple teaming security operations (SOC) incident response and detection engineering. Creation of or contributions to open-source tools or projects CTF participation or public research/blogging. What We Look For We are looking for a senior operator that can operate autonomously and bring new strategic approaches to discovering and evaluating the firm’s attack surface to improve the overall security posture. We are seeking a seasoned operator to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What We Offer EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina Hungary India the Philippines Poland Sri Lanka Mexico Spain and the United Kingdom – and with teams from all EY service lines geographies and sectors playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people learning skills and insights that will stay with you throughout your career. Continuous learning You’ll develop the mindset and skills to navigate whatever comes next. Success as defined by you We’ll provide the tools and flexibility so you can make a meaningful impact your way. Transformative leadership We’ll give you the insights coaching and confidence to be the leader the world needs. Diverse and inclusive culture You’ll be embraced for who you are and empowered to use your voice to help others find theirs. About EY EY Building a better working world EY exists to build a better working world helping to create long-term value for clients people and society and build trust in the capital markets. Enabled by data and technology diverse EY teams in over 150 countries provide trust through assurance and help clients grow transform and operate. Working across assurance consulting law strategy tax and transactions EY teams ask better questions to find new answers for the complex issues facing our world today. If you can demonstrate that you meet the criteria above please contact us as soon as possible. The Exceptional EY Experience. It’s Yours To Build. In compliance with the requirements of the Whistleblower Protection Act our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions . Any misconduct should be reported through the EY Ethics Hotline.

Global Red Team AI Engineer, AVP

Jersey City, NJ

Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the world’s leading financial groups. Across the globe we’re 150000 colleagues striving to make a difference for every client organization and community we serve. We stand for our values building long-term relationships serving society and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group it’s part of our culture to put people first listen to new and diverse ideas and collaborate toward greater innovation speed and agility. This means investing in talent technologies and tools that empower you to own your career. Join MUFG where being inspired is expected and making a meaningful impact is rewarded. The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The Assistant Vice President Red Team & AI Security supports the planning execution and reporting of adversary simulation control validation and AI security assessment activities across the enterprise. This role is hands-on and operator-focused combining offensive security tradecraft with AI analysis responsibilities to help identify exploitable weaknesses validate defensive controls and translate findings into practical remediation guidance. Key Responsibilities Operational Planning & Engagement Support Support the planning and execution of Red Team Purple Team adversary simulation and control validation engagements. Assist with target research scope development rules of engagement infrastructure preparation and operational documentation. Coordinate with defensive engineering risk and business stakeholders to ensure engagements are well-structured and findings are actionable. Red Team Execution Perform hands-on offensive security testing across network endpoint identity application cloud and selected physical attack surfaces. Execute techniques such as reconnaissance initial access validation privilege escalation lateral movement persistence simulation and control evasion in approved environments. Develop modify and safely use scripts payloads tooling and tradecraft to support realistic adversary emulation. AI Security Responsibilities Support adversarial testing of AI and LLM systems including prompt injection data leakage tool misuse model behavior abuse and guardrail bypass scenarios. Analyze AI-enabled applications copilots automation workflows agents plugins APIs and data integrations for security and abuse risks. Document AI security observations in clear business and technical terms including risk impact exploitability control gaps and recommended remediation. Use AI-assisted analysis responsibly to accelerate research data review reporting detection mapping and test-case development. Track emerging AI threats attacker use of AI and relevant industry guidance to inform Red Team scenarios and validation priorities. Threat Tradecraft & Capability Development Drive research into real‑world threat actor TTPs and emerging AI‑enabled attack techniques. Sponsor development of red team tools scripts and repeatable methodologies to increase realism scale and efficiency. Establish standards for tooling governance safe use and audit readiness. Reporting Documentation & Collaboration Prepare engagement notes evidence packages attack narratives findings remediation guidance and executive-ready summaries. Map observations to relevant frameworks controls detections and business risk themes where appropriate. Partner with blue team cyber defense engineering governance and application teams to validate remediation and improve control effectiveness. Qualifications Experience 4+ years of experience in offensive security red team operations penetration testing application security cloud security cyber defense or related security assessment roles. Hands-on experience supporting security assessments adversary emulation control validation vulnerability analysis or threat-informed testing. Exposure to AI security LLM testing AI governance data security machine learning workflows or secure use of AI-assisted tools is preferred. Technical Skills Working knowledge of common attack techniques across Windows Linux Active Directory web applications APIs cloud platforms and identity systems. Ability to write or modify scripts and tools using languages such as Python PowerShell Bash JavaScript or similar. Familiarity with offensive security tools vulnerability validation command-and-control concepts detection engineering concepts and MITRE ATT&CK mapping. Understanding of AI security risks such as prompt injection excessive agency insecure tool use sensitive data exposure insecure plugins model abuse and AI-enabled social engineering. Education & Certifications (Preferred) Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering Data Science or equivalent experience. Security certifications such as OSCP GPEN GWAPT GCIH GCIA GSEC CISSP or similar are preferred but not required. Familiarity with regulatory risk or control frameworks such as NIST FFIEC GLBA SOX PCI or internal control standards is beneficial. Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position. The typical base pay range for this role is as follows New York / New Jersey $90k-$153k Non–New York / New Jersey $90k-$141k depending on job-related knowledge skills experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits retirement plans educational assistance and training programs income replacement for qualified employees with disabilities paid maternity and parental bonding leave and paid vacation sick days and holidays. For more information on our Total Rewards package please click the link below. Our hybrid work schedule is four days on-site and work remotely one day per week. MUFG Benefits Summary We will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance (iii) the Los Angeles County Fair Chance Ordinance and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment if any. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified. We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race color national origin religion gender expression gender identity sex age ancestry marital status protected veteran and military status disability medical condition sexual orientation genetic information or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal state or local law.

Global Red Team AI Engineer, AVP

Tempe, AZ

Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the world’s leading financial groups. Across the globe we’re 150000 colleagues striving to make a difference for every client organization and community we serve. We stand for our values building long-term relationships serving society and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group it’s part of our culture to put people first listen to new and diverse ideas and collaborate toward greater innovation speed and agility. This means investing in talent technologies and tools that empower you to own your career. Join MUFG where being inspired is expected and making a meaningful impact is rewarded. The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The Assistant Vice President Red Team & AI Security supports the planning execution and reporting of adversary simulation control validation and AI security assessment activities across the enterprise. This role is hands-on and operator-focused combining offensive security tradecraft with AI analysis responsibilities to help identify exploitable weaknesses validate defensive controls and translate findings into practical remediation guidance. Key Responsibilities Operational Planning & Engagement Support Support the planning and execution of Red Team Purple Team adversary simulation and control validation engagements. Assist with target research scope development rules of engagement infrastructure preparation and operational documentation. Coordinate with defensive engineering risk and business stakeholders to ensure engagements are well-structured and findings are actionable. Red Team Execution Perform hands-on offensive security testing across network endpoint identity application cloud and selected physical attack surfaces. Execute techniques such as reconnaissance initial access validation privilege escalation lateral movement persistence simulation and control evasion in approved environments. Develop modify and safely use scripts payloads tooling and tradecraft to support realistic adversary emulation. AI Security Responsibilities Support adversarial testing of AI and LLM systems including prompt injection data leakage tool misuse model behavior abuse and guardrail bypass scenarios. Analyze AI-enabled applications copilots automation workflows agents plugins APIs and data integrations for security and abuse risks. Document AI security observations in clear business and technical terms including risk impact exploitability control gaps and recommended remediation. Use AI-assisted analysis responsibly to accelerate research data review reporting detection mapping and test-case development. Track emerging AI threats attacker use of AI and relevant industry guidance to inform Red Team scenarios and validation priorities. Threat Tradecraft & Capability Development Drive research into real‑world threat actor TTPs and emerging AI‑enabled attack techniques. Sponsor development of red team tools scripts and repeatable methodologies to increase realism scale and efficiency. Establish standards for tooling governance safe use and audit readiness. Reporting Documentation & Collaboration Prepare engagement notes evidence packages attack narratives findings remediation guidance and executive-ready summaries. Map observations to relevant frameworks controls detections and business risk themes where appropriate. Partner with blue team cyber defense engineering governance and application teams to validate remediation and improve control effectiveness. Qualifications Experience 4+ years of experience in offensive security red team operations penetration testing application security cloud security cyber defense or related security assessment roles. Hands-on experience supporting security assessments adversary emulation control validation vulnerability analysis or threat-informed testing. Exposure to AI security LLM testing AI governance data security machine learning workflows or secure use of AI-assisted tools is preferred. Technical Skills Working knowledge of common attack techniques across Windows Linux Active Directory web applications APIs cloud platforms and identity systems. Ability to write or modify scripts and tools using languages such as Python PowerShell Bash JavaScript or similar. Familiarity with offensive security tools vulnerability validation command-and-control concepts detection engineering concepts and MITRE ATT&CK mapping. Understanding of AI security risks such as prompt injection excessive agency insecure tool use sensitive data exposure insecure plugins model abuse and AI-enabled social engineering. Education & Certifications (Preferred) Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering Data Science or equivalent experience. Security certifications such as OSCP GPEN GWAPT GCIH GCIA GSEC CISSP or similar are preferred but not required. Familiarity with regulatory risk or control frameworks such as NIST FFIEC GLBA SOX PCI or internal control standards is beneficial. Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position. The typical base pay range for this role is as follows New York / New Jersey $90k-$153k Non–New York / New Jersey $90k-$141k depending on job-related knowledge skills experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits retirement plans educational assistance and training programs income replacement for qualified employees with disabilities paid maternity and parental bonding leave and paid vacation sick days and holidays. For more information on our Total Rewards package please click the link below. Our hybrid work schedule is four days on-site and work remotely one day per week. MUFG Benefits Summary We will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance (iii) the Los Angeles County Fair Chance Ordinance and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment if any. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified. We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race color national origin religion gender expression gender identity sex age ancestry marital status protected veteran and military status disability medical condition sexual orientation genetic information or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal state or local law.

Manager, Pentesting

México, Mexico

About KTSA We are KTSA – KPMG Technology Services Americas. A Service Delivery Center of KPMG US with offices in Mexico City Guadalajara and a growing network of remote talent across the country. We deliver high-value technology consulting and corporate support services to KPMG US and its clients. At KTSA our Employer Value Proposition is clear Explore . Explore isn’t just a word — it’s how we grow lead and thrive. It’s the mindset that drives our culture and shapes every opportunity Experience a collaborative inclusive and multicultural workplace where you belong. Excel by creating impact and leaving your mark on global projects. Expand your potential with real career paths learning programs and mentorship. Express your individuality — come as you are and thrive as your authentic self. And because we know that thriving at work also means thriving in life we back this mindset with KTSAMÁS our total rewards program designed to support your well-being goals and personal milestones. Responsibilities • Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities control gaps and practical paths to remediation. • Plan and execute penetration testing activities across web applications APIs external and internal networks cloud-hosted environments and supporting infrastructure as applicable to the engagement scope. • Assess common application and API security weaknesses including authentication flaws authorization issues injection vulnerabilities business logic flaws insecure configurations and exposure of sensitive data. • Document findings clearly including business impact technical evidence risk context reproducible steps and practical remediation guidance for member firm stakeholders. • Facilitate security assessments and support the resolution of identified vulnerabilities through clear communication retesting and coordination with application infrastructure and security teams. • Communicate assessment results to technical and non-technical stakeholders through written reports walkthroughs and remediation discussions. • Stay current with common and emerging security threats penetration testing techniques tooling and assessment methodologies relevant to application and network security. Requirements. • Bachelor’s degree with 5+ years of practical experience in cybersecurity f ocused on application penetration testing network penetration testing and related cloud security assessment activities. • Strong hands-on experience performing manual web application API network and infrastructure penetration testing including validation beyond automated scanning tools. • Strong familiarity with frameworks and methodologies such as MITRE ATT&CK OWASP Top 10 OWASP API Security Top 10 PTES. • Relevant certifications such as OSCP GPEN GWAPT OSCE GXPN or similar are highly preferred. CISSP and Azure or other cloud platform certifications are a plus. • Solid foundation in network application and cloud security concepts with hands-on experience identifying validating and explaining vulnerabilities in real-world environments. • Proficiency in scripting and automation with experience in Python Bash or PowerShell. • Experience with common and emerging security threats scanning tools exploitation techniques assessment methodologies and secure remediation practices. • Demonstrated understanding of security principles IT security controls and related technologies and products. • Strong verbal and written communication problem solving analytical and independent judgment skills to support an environment driven by customer service collaboration and teamwork. • Experience working directly with clients project stakeholders or business units to clarify scope communicate findings and support remediation efforts. Expand your possibilities with KTSA through KTSAMÁS where you can access Extended maternity paternity and adoption leaves Above-market vacation benefits Learning opportunities training and certification programs Extended marriage leave and daycare support Wellness and Employee Assistance Programs (EAP) Comprehensive medical plan life insurance car insurance and funeral assistance Visit www.ktsa.com.mx to learn more. At KTSA we celebrate and support everyone’s individuality. We do not discriminate against any race religion color national origin gender sexual orientation gender identity or expression age marital status or disability. We are supportive of helping you to achieve a balance between your home and work demands. We are happy to discuss specific requirements and our range of flexible working arrangements could be of interest. Please ask to find out more. We strongly state that we DO NOT require a certificate of non-pregnancy or HIV in order to participate in any of our processes. Explore KTSA we dare to be different! Home - KTSA KTSA - KPMG Technology Services of Americas

Counter-Threat Intelligence Engineer

Remote United States

Job Overview Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify understand and counter cyber threats that could impact our learners educators associates platforms data and business operations. This role combines threat intelligence ethical hacking exposure validation adversary emulation and security engineering to turn emerging threat information into actionable defenses. The engineer will work closely with Security Operations IT Operations Risk Legal Compliance Product Engineering and business stakeholders to help reduce attack surface improve detection logic support incident response and translate technical findings into clear recommendations. The ideal candidate brings hands-on offensive security experience exceptional analytical judgment and the ability to communicate threat context in a way that drives practical remediation and measurable risk reduction. Job Responsibilities Collect analyze and operationalize strategic tactical and operational threat intelligence from trusted internal and external sources including indicators of compromise adversary tactics techniques and procedures emerging vulnerabilities and targeted threat activity. Perform adversary-focused research and ethical hacking activities with authorization to validate exposures identify likely attack paths and recommend defensive improvements across endpoints cloud services applications identity platforms networks and third-party integrations. Partner with Security Operations to create tune and validate detections playbooks threat hunting hypotheses and response workflows in data log pipelines SIEM XDR EDR vulnerability management and related security tools. Support Continuous Threat Exposure Management efforts by helping scope assets discover exposures prioritize findings based on business risk validate exploitability and coordinate mobilization of remediation activities with IT infrastructure engineering and business owners. Produce concise actionable threat intelligence reports briefings and technical recommendations for audiences ranging from security analysts to senior leadership emphasizing relevance impact urgency and practical next steps. Contribute to incident response investigations by enriching alerts with threat context malware or phishing analysis infrastructure research attack timeline reconstruction and lessons learned. Maintain awareness of threat actor tradecraft vulnerability exploitation trends cloud and identity attacks education-sector threats data protection risks and changes in attacker use of automation and artificial intelligence. Use independent judgment to make recommendations on defensive priorities detection improvements risk acceptance considerations and escalation paths while staying aligned with Cambium policies standards and governance expectations. Job Requirements 5+ years of progressive cybersecurity experience with at least 2 years in threat intelligence ethical hacking penetration testing detection engineering security operations incident response vulnerability management or a closely related role. Certified Ethical Hacker (CEH) certification is highly preferred similar hands-on offensive security or threat intelligence certifications may be considered such as OSCP GPEN CompTIA PenTest+ CPENT eJPT GCTI CTIA or equivalent practical experience. Proven working knowledge of the cyber kill chain MITRE ATT&CK common attack techniques malware and phishing behaviors cloud and identity threats vulnerability exploitation attacker infrastructure and defensive countermeasures. Hands-on experience with security tools and data sources such as SIEM XDR/EDR vulnerability scanners threat intelligence platforms cloud security tools identity logs endpoint telemetry network telemetry and ticketing/workflow platforms. Ability to write clear threat intelligence summaries detection recommendations executive briefings remediation guidance and technical documentation that can be acted on by cross-functional teams. Experience conducting authorized security testing adversary emulation attack surface analysis detection validation or threat hunts in a disciplined evidence-based and policy-aligned manner. Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering or a related field preferred equivalent professional experience and certifications may be considered. High judgment strong ethics discretion with sensitive information collaborative communication style and commitment to protecting confidential proprietary student customer associate and business data. Preferred Qualifications Experience in education technology SaaS cloud-first remote-first or regulated environments. Experience building threat hunting content Sigma/YARA rules KQL/SPL queries detection-as-code or automation for enrichment and triage. Familiarity with scripting or automation using Python PowerShell Bash APIs or SOAR-style workflows. Working knowledge of data privacy secure software development third-party risk and compliance frameworks such as ISO 27001 SOC 2 NIST CSF or NIST SP 800-series guidance. To learn more about our organization and the exciting work we do visit www.cambiumlearning.com Remote First Work Environment Our Remote First approach gives employees the flexibility and trust they need to effectively balance work with life. It creates a culture in which all employees are valued and where success is measured in results. It allows us to work collaboratively inclusively and for greater positive impact regardless of our individual locations. If you will be working remotely either occasionally or on a permanent basis you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload. The successful candidate will be expected to actively participate in video-based interviews during the recruiting process and ongoing virtual meetings with their camera on as part of their role. To maintain confidentiality and ensure a fair evaluation process the use of note-taking tools reference materials or AI-powered tools (including generative AI language models or similar technologies) during interviews or other selection activities is prohibited unless prior written approval has been obtained from the People Experience team. If you require an exception for medical accessibility or other reasons please contact your Talent Acquisition team member to discuss accommodations in advance. As part of our Remote-First benefits Cambium offers reimbursement to help cover the cost of setting up your home or remote office. An Equal Opportunity Employer We are dedicated to fostering a culture that celebrates unique backgrounds ideas and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race color age religion sex (including pregnancy gender gender identity/expression or sexual orientation) national origin protected veteran status disability or genetic information (including family medical history). We will provide reasonable accommodations for qualified individuals with disabilities. You may request an accommodation during the recruiting process with your Talent Acquisition team member.

unlock: sign-up for free / login and use the searches from your home page
🔥 job listings updated in real time


For the 10 positions listed above we've analyzed the salary ranges, where available, and the resulting overall salary range is: 90K - 153K USD.

For 12 similar GPEN position(s) we've listed yesterday we've checked the salary ranges, as posted, and the resulting overall range is: 90K - 153K USD.

For 181 similar GPEN position(s) we've listed in the previous 30 days we've processed the salary ranges data as posted by employers in job descriptions and the resulting overall range is: 85K - 280K USD.

View highest-paying job

Note: If any discrepancies or 'wild' numbers appear this could be because of: typos in job postings, data source errors, ghost jobs, etc. We do not modify salary data inserted in JDs by employers nor use estimates.


Login & search by other job titles, a specific location or any keyword.
Additional custom search filters are available once you login.