Search 403 Remote GWAPT Jobs

403 remote jobs

Senior Offensive Security Engineer - Pentester

Chicago, IL

Job Description At Bank of America we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients teammates communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace attracting and developing exceptional talent supporting our teammates’ physical emotional and financial wellness recognizing and rewarding performance and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America you can build a successful career with opportunities to learn grow and make an impact. Join us! Job Description Are you passionate about cybersecurity and looking to work with some of the best information security professionals in the world in challenging environments? Bank of America is hiring top talent to join our team. You bring your talent and passion and we’ll provide you with an opportunity to shine and grow. The Cyber Security Assurance Division is looking for a Senior Full Stack Pentester to join a team of world-class offensive security professionals. In this role you will diligently hunt for high-risk vulnerabilities across the bank’s global technology environment. Understanding security policy and compliance is important but in this role your focus is to identify exploitable vulnerabilities in critical systems ones that can bring about that “nightmare scenario.” This is a highly-technical role that requires broad technical knowledge a deep understanding of threats and a hacker mentality. You will lead and participate in collaborative technical assessments that leverage a wide range of penetration testing techniques (reconnaissance weaponization delivery exploitation) to identify and prove the concept of high-risk vulnerabilities across a variety of technologies. Your strong problem-solving skills practical demonstration of technical competency and lateral thinking will contribute to our team-first culture of collaboration and impactful findings. This senior technical role is responsible for leading and performing assessments of the bank's technologies applications and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research understanding the bank's security policy working with appropriate partners to complete assessments identifying misconfigurations and vulnerabilities to achieve security impact and reporting on the associated risk. These individuals partner closely with security partners CIO clients and multiple lines of business. You will coordinate with senior leadership on development projects share your knowledge and experience by mentoring junior engineers and assist with monitoring and response functions so those teams can practice and improve their capability to respond to a realistic threat actor. Required Skills Minimum of 5+ years of professional offensive security experience Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear precise terms to technical and non-technical audiences. Must be very proficient with the common tools associated with penetration testing (Burp Suite Metasploit nmap etc.). Must have a solid understanding of voice and data networks major operating systems active directory their associated peripherals and a strong desire to learn new technologies and skill sets. Must demonstrate knowledge of tactics techniques and procedures associated with malicious activity an understanding of industry classifications and frameworks and the ability to chain vulnerabilities in the advanced exploitation of systems. Must be proficient in report delivery and technical documentation of vulnerabilities. Must be able to effectively code in a programming or scripting language (Python Java C etc.) Desirable Skills Certifications OSCP GPEN GXPN OSED OSEP OSWE OSCE GWAPT Ability to work remotely if/when necessary Previous experience working in the financial industry Experience with hardware hacking embedded systems analysis and IoT hacking This job will be open and accepting applications for a minimum of seven days from the date it was posted. Shift 1st shift (United States of America) Hours Per Week 40

Global Red Team AI Engineer, AVP

Jersey City, NJ

Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the world’s leading financial groups. Across the globe we’re 150000 colleagues striving to make a difference for every client organization and community we serve. We stand for our values building long-term relationships serving society and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group it’s part of our culture to put people first listen to new and diverse ideas and collaborate toward greater innovation speed and agility. This means investing in talent technologies and tools that empower you to own your career. Join MUFG where being inspired is expected and making a meaningful impact is rewarded. The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The Assistant Vice President Red Team & AI Security supports the planning execution and reporting of adversary simulation control validation and AI security assessment activities across the enterprise. This role is hands-on and operator-focused combining offensive security tradecraft with AI analysis responsibilities to help identify exploitable weaknesses validate defensive controls and translate findings into practical remediation guidance. Key Responsibilities Operational Planning & Engagement Support Support the planning and execution of Red Team Purple Team adversary simulation and control validation engagements. Assist with target research scope development rules of engagement infrastructure preparation and operational documentation. Coordinate with defensive engineering risk and business stakeholders to ensure engagements are well-structured and findings are actionable. Red Team Execution Perform hands-on offensive security testing across network endpoint identity application cloud and selected physical attack surfaces. Execute techniques such as reconnaissance initial access validation privilege escalation lateral movement persistence simulation and control evasion in approved environments. Develop modify and safely use scripts payloads tooling and tradecraft to support realistic adversary emulation. AI Security Responsibilities Support adversarial testing of AI and LLM systems including prompt injection data leakage tool misuse model behavior abuse and guardrail bypass scenarios. Analyze AI-enabled applications copilots automation workflows agents plugins APIs and data integrations for security and abuse risks. Document AI security observations in clear business and technical terms including risk impact exploitability control gaps and recommended remediation. Use AI-assisted analysis responsibly to accelerate research data review reporting detection mapping and test-case development. Track emerging AI threats attacker use of AI and relevant industry guidance to inform Red Team scenarios and validation priorities. Threat Tradecraft & Capability Development Drive research into real‑world threat actor TTPs and emerging AI‑enabled attack techniques. Sponsor development of red team tools scripts and repeatable methodologies to increase realism scale and efficiency. Establish standards for tooling governance safe use and audit readiness. Reporting Documentation & Collaboration Prepare engagement notes evidence packages attack narratives findings remediation guidance and executive-ready summaries. Map observations to relevant frameworks controls detections and business risk themes where appropriate. Partner with blue team cyber defense engineering governance and application teams to validate remediation and improve control effectiveness. Qualifications Experience 4+ years of experience in offensive security red team operations penetration testing application security cloud security cyber defense or related security assessment roles. Hands-on experience supporting security assessments adversary emulation control validation vulnerability analysis or threat-informed testing. Exposure to AI security LLM testing AI governance data security machine learning workflows or secure use of AI-assisted tools is preferred. Technical Skills Working knowledge of common attack techniques across Windows Linux Active Directory web applications APIs cloud platforms and identity systems. Ability to write or modify scripts and tools using languages such as Python PowerShell Bash JavaScript or similar. Familiarity with offensive security tools vulnerability validation command-and-control concepts detection engineering concepts and MITRE ATT&CK mapping. Understanding of AI security risks such as prompt injection excessive agency insecure tool use sensitive data exposure insecure plugins model abuse and AI-enabled social engineering. Education & Certifications (Preferred) Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering Data Science or equivalent experience. Security certifications such as OSCP GPEN GWAPT GCIH GCIA GSEC CISSP or similar are preferred but not required. Familiarity with regulatory risk or control frameworks such as NIST FFIEC GLBA SOX PCI or internal control standards is beneficial. Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position. The typical base pay range for this role is as follows New York / New Jersey $90k-$153k Non–New York / New Jersey $90k-$141k depending on job-related knowledge skills experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits retirement plans educational assistance and training programs income replacement for qualified employees with disabilities paid maternity and parental bonding leave and paid vacation sick days and holidays. For more information on our Total Rewards package please click the link below. Our hybrid work schedule is four days on-site and work remotely one day per week. MUFG Benefits Summary We will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance (iii) the Los Angeles County Fair Chance Ordinance and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment if any. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified. We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race color national origin religion gender expression gender identity sex age ancestry marital status protected veteran and military status disability medical condition sexual orientation genetic information or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal state or local law.

Global Red Team AI Engineer, AVP

Tempe, AZ

Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the world’s leading financial groups. Across the globe we’re 150000 colleagues striving to make a difference for every client organization and community we serve. We stand for our values building long-term relationships serving society and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group it’s part of our culture to put people first listen to new and diverse ideas and collaborate toward greater innovation speed and agility. This means investing in talent technologies and tools that empower you to own your career. Join MUFG where being inspired is expected and making a meaningful impact is rewarded. The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The Assistant Vice President Red Team & AI Security supports the planning execution and reporting of adversary simulation control validation and AI security assessment activities across the enterprise. This role is hands-on and operator-focused combining offensive security tradecraft with AI analysis responsibilities to help identify exploitable weaknesses validate defensive controls and translate findings into practical remediation guidance. Key Responsibilities Operational Planning & Engagement Support Support the planning and execution of Red Team Purple Team adversary simulation and control validation engagements. Assist with target research scope development rules of engagement infrastructure preparation and operational documentation. Coordinate with defensive engineering risk and business stakeholders to ensure engagements are well-structured and findings are actionable. Red Team Execution Perform hands-on offensive security testing across network endpoint identity application cloud and selected physical attack surfaces. Execute techniques such as reconnaissance initial access validation privilege escalation lateral movement persistence simulation and control evasion in approved environments. Develop modify and safely use scripts payloads tooling and tradecraft to support realistic adversary emulation. AI Security Responsibilities Support adversarial testing of AI and LLM systems including prompt injection data leakage tool misuse model behavior abuse and guardrail bypass scenarios. Analyze AI-enabled applications copilots automation workflows agents plugins APIs and data integrations for security and abuse risks. Document AI security observations in clear business and technical terms including risk impact exploitability control gaps and recommended remediation. Use AI-assisted analysis responsibly to accelerate research data review reporting detection mapping and test-case development. Track emerging AI threats attacker use of AI and relevant industry guidance to inform Red Team scenarios and validation priorities. Threat Tradecraft & Capability Development Drive research into real‑world threat actor TTPs and emerging AI‑enabled attack techniques. Sponsor development of red team tools scripts and repeatable methodologies to increase realism scale and efficiency. Establish standards for tooling governance safe use and audit readiness. Reporting Documentation & Collaboration Prepare engagement notes evidence packages attack narratives findings remediation guidance and executive-ready summaries. Map observations to relevant frameworks controls detections and business risk themes where appropriate. Partner with blue team cyber defense engineering governance and application teams to validate remediation and improve control effectiveness. Qualifications Experience 4+ years of experience in offensive security red team operations penetration testing application security cloud security cyber defense or related security assessment roles. Hands-on experience supporting security assessments adversary emulation control validation vulnerability analysis or threat-informed testing. Exposure to AI security LLM testing AI governance data security machine learning workflows or secure use of AI-assisted tools is preferred. Technical Skills Working knowledge of common attack techniques across Windows Linux Active Directory web applications APIs cloud platforms and identity systems. Ability to write or modify scripts and tools using languages such as Python PowerShell Bash JavaScript or similar. Familiarity with offensive security tools vulnerability validation command-and-control concepts detection engineering concepts and MITRE ATT&CK mapping. Understanding of AI security risks such as prompt injection excessive agency insecure tool use sensitive data exposure insecure plugins model abuse and AI-enabled social engineering. Education & Certifications (Preferred) Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering Data Science or equivalent experience. Security certifications such as OSCP GPEN GWAPT GCIH GCIA GSEC CISSP or similar are preferred but not required. Familiarity with regulatory risk or control frameworks such as NIST FFIEC GLBA SOX PCI or internal control standards is beneficial. Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position. The typical base pay range for this role is as follows New York / New Jersey $90k-$153k Non–New York / New Jersey $90k-$141k depending on job-related knowledge skills experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits retirement plans educational assistance and training programs income replacement for qualified employees with disabilities paid maternity and parental bonding leave and paid vacation sick days and holidays. For more information on our Total Rewards package please click the link below. Our hybrid work schedule is four days on-site and work remotely one day per week. MUFG Benefits Summary We will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance (iii) the Los Angeles County Fair Chance Ordinance and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment if any. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified. We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race color national origin religion gender expression gender identity sex age ancestry marital status protected veteran and military status disability medical condition sexual orientation genetic information or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal state or local law.

Manager, Pentesting

México, Mexico

About KTSA We are KTSA – KPMG Technology Services Americas. A Service Delivery Center of KPMG US with offices in Mexico City Guadalajara and a growing network of remote talent across the country. We deliver high-value technology consulting and corporate support services to KPMG US and its clients. At KTSA our Employer Value Proposition is clear Explore . Explore isn’t just a word — it’s how we grow lead and thrive. It’s the mindset that drives our culture and shapes every opportunity Experience a collaborative inclusive and multicultural workplace where you belong. Excel by creating impact and leaving your mark on global projects. Expand your potential with real career paths learning programs and mentorship. Express your individuality — come as you are and thrive as your authentic self. And because we know that thriving at work also means thriving in life we back this mindset with KTSAMÁS our total rewards program designed to support your well-being goals and personal milestones. Responsibilities • Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities control gaps and practical paths to remediation. • Plan and execute penetration testing activities across web applications APIs external and internal networks cloud-hosted environments and supporting infrastructure as applicable to the engagement scope. • Assess common application and API security weaknesses including authentication flaws authorization issues injection vulnerabilities business logic flaws insecure configurations and exposure of sensitive data. • Document findings clearly including business impact technical evidence risk context reproducible steps and practical remediation guidance for member firm stakeholders. • Facilitate security assessments and support the resolution of identified vulnerabilities through clear communication retesting and coordination with application infrastructure and security teams. • Communicate assessment results to technical and non-technical stakeholders through written reports walkthroughs and remediation discussions. • Stay current with common and emerging security threats penetration testing techniques tooling and assessment methodologies relevant to application and network security. Requirements. • Bachelor’s degree with 5+ years of practical experience in cybersecurity f ocused on application penetration testing network penetration testing and related cloud security assessment activities. • Strong hands-on experience performing manual web application API network and infrastructure penetration testing including validation beyond automated scanning tools. • Strong familiarity with frameworks and methodologies such as MITRE ATT&CK OWASP Top 10 OWASP API Security Top 10 PTES. • Relevant certifications such as OSCP GPEN GWAPT OSCE GXPN or similar are highly preferred. CISSP and Azure or other cloud platform certifications are a plus. • Solid foundation in network application and cloud security concepts with hands-on experience identifying validating and explaining vulnerabilities in real-world environments. • Proficiency in scripting and automation with experience in Python Bash or PowerShell. • Experience with common and emerging security threats scanning tools exploitation techniques assessment methodologies and secure remediation practices. • Demonstrated understanding of security principles IT security controls and related technologies and products. • Strong verbal and written communication problem solving analytical and independent judgment skills to support an environment driven by customer service collaboration and teamwork. • Experience working directly with clients project stakeholders or business units to clarify scope communicate findings and support remediation efforts. Expand your possibilities with KTSA through KTSAMÁS where you can access Extended maternity paternity and adoption leaves Above-market vacation benefits Learning opportunities training and certification programs Extended marriage leave and daycare support Wellness and Employee Assistance Programs (EAP) Comprehensive medical plan life insurance car insurance and funeral assistance Visit www.ktsa.com.mx to learn more. At KTSA we celebrate and support everyone’s individuality. We do not discriminate against any race religion color national origin gender sexual orientation gender identity or expression age marital status or disability. We are supportive of helping you to achieve a balance between your home and work demands. We are happy to discuss specific requirements and our range of flexible working arrangements could be of interest. Please ask to find out more. We strongly state that we DO NOT require a certificate of non-pregnancy or HIV in order to participate in any of our processes. Explore KTSA we dare to be different! Home - KTSA KTSA - KPMG Technology Services of Americas

Staff AppSec Engineer

Remote United States

Our Purpose At SentinelOne we are driven by a clear purpose to give the advantage to those who secure our future. As AI reshapes how organizations build operate and innovate the responsibility to protect them becomes more critical than ever. When you join SentinelOne your work helps protect global enterprises critical infrastructure and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real measurable and global you will find purpose here. About Us SentinelOne is a company at the intersection of AI and security pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint cloud identity data and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics intelligent automation and a unified data foundation we reduce noise simplify complexity and empower security teams to focus on what truly matters. Our teams are builders problem-solvers and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented mission-driven people we invite you to help us build a safer future for humanity. What Are We Looking For? We're looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business and we enable every team member regardless of role or level to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions experiment thoughtfully and apply what they learn to drive better faster smarter outcomes. SentinelOne recently launched Wayfinder Frontier AI Services — a new customer-facing offering that pairs frontier AI models with our most seasoned offensive and defensive experts. The service extends our Wayfinder portfolio (Threat Hunting MDR Essentials MDR Elite Incident Readiness & Response) into proactive AI-accelerated exposure management. In this role you'll do more than review code — you'll become the trusted advisor customers turn to on Go Java and C-based source code assessment. You'll work directly on top of the output of our agentic code scanning pipeline validate findings with human judgment deliver results to diverse technical and leadership audiences and shape the methodology that scales the practice. What Will You Do? Primary responsibilities include Lead Wayfinder Frontier AI Services customer engagements end-to-end scope the work deliver the technical findings and present results to executive and technical stakeholders. Review and triage findings from our agentic code scanning pipeline against customer Go Java and C codebases. Validate true positives eliminate noise and ensure every finding that reaches the customer is a decision they can act on. Conduct deep code review across Go Java and C code and common frameworks. Present findings to stake holders translate technical risk into business impact and map exposures into end-to-end exploitation chains.. Author and maintain SAST rule packs that scale across the customer base and partner with our AI/ML engineers to improve our agentic scanning engine. Provide expert remediation guidance to customer development teams and validate fixes through follow-up review. Work closely with our engineering teams to enhance our agentic code scanning pipeline and reduce false positives. Mentor senior AppSec engineers and software-focused threat hunters to elevate team technical standards. Define and refine the service line's core methodologies engagement playbooks and scoping templates. What Skills and Knowledge Will You Bring? Ideal candidates will have 7+ years in application security or product security with a strong software development background. Proven track record translating complex findings into technical and executive-level debriefs. Excellent written and verbal communication is essential. Experience delivering customer-facing or consulting-style engagements end-to-end comfortable in a distributed remote organization. Expert-level of at least two out of the three Go Java and C in the past you've identified and explained vulnerabilities at the framework level not just the application level. Expert-level of at least two out of the three Go Java and C - understanding of vulnerabilities and secure coding methodologies. Mastery of OWASP Top 10 CWE Top 25 and modern authentication infrastructure (SAML OAuth OIDC JWT internals). Experience driving an application through ASVS Level 4 verification. Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines familiarity with AI-assisted code review workflows and validating findings produced by automated and agentic analysis pipelines. Strong threat modeling experience throughout the secure SDLC. Fluency with Git-based source control and CI/CD pipelines including build-pipeline security controls runner hardening and release-gate enforcement. Experience with AI accelerated development / code scanning methodologies. Nice to Have Working depth in Python (Django/Flask) and Node.js (Express) for cross-language reviews. Reverse engineering of compiled Go Java and C (IDA Pro Binary Ninja Ghidra dnspy ilspy JAD CFR). OSWE CSSLP GWAPT published CVEs or conference talks. Familiarity with SOC 2 ISO 27001 or FedRAMP control mapping. Why SentinelOne? AI is redefining how the world operates and rewriting the rules of security in real time and SentinelOne was built for this moment. From day one we architected an AI-native platform designed to operate at machine speed not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together this is that place. We invest in our Sentinels with comprehensive competitive benefits designed to support you and your family Equity & Rewards Restricted Stock Units (RSUs) Employee Stock Purchase Plan (ESPP) Time Off & Wellbeing Flexible time off Paid company holidays and paid sick time Gender-neutral parental leave Grandparent leave Insurance & Financial Security Medical dental and vision coverage 401(k) retirement plan with company match Life and disability insurance Health and dependent care FSA Voluntary benefits (hospital accident critical illness) Employee Assistance Program (EAP) ARAG pre-paid legal Nationwide pet insurance Cancer Care program Global business travel medical insurance Work Perks & Flexibility Home office allowance Mobile phone reimbursement Wellness & Lifestyle Wellness coach Wellness/gym reimbursement Fertility coverage Adoption & surrogacy reimbursement SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race religion color national origin gender (including pregnancy childbirth or related medical conditions) sexual orientation gender identity gender expression age status as a protected veteran status as an individual with a disability or other applicable legally protected characteristics. SentinelOne participates in the E-Verify Program for all U.S. based roles.

Staff AppSec Engineer

Remote United States

Our Purpose At SentinelOne we are driven by a clear purpose to give the advantage to those who secure our future. As AI reshapes how organizations build operate and innovate the responsibility to protect them becomes more critical than ever. When you join SentinelOne your work helps protect global enterprises critical infrastructure and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real measurable and global you will find purpose here. About Us SentinelOne is a company at the intersection of AI and security pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint cloud identity data and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics intelligent automation and a unified data foundation we reduce noise simplify complexity and empower security teams to focus on what truly matters. Our teams are builders problem-solvers and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented mission-driven people we invite you to help us build a safer future for humanity. What Are We Looking For? We're looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business and we enable every team member regardless of role or level to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions experiment thoughtfully and apply what they learn to drive better faster smarter outcomes. SentinelOne recently launched Wayfinder Frontier AI Services — a new customer-facing offering that pairs frontier AI models with our most seasoned offensive and defensive experts. The service extends our Wayfinder portfolio (Threat Hunting MDR Essentials MDR Elite Incident Readiness & Response) into proactive AI-accelerated exposure management. In this role you'll do more than review code — you'll become the trusted advisor customers turn to on C C++ Rust and Java source code assessments. You'll work directly on top of the output of our agentic code scanning pipeline validate findings with human judgment deliver results to diverse technical and leadership audiences and shape the methodology that scales the practice. What Will You Do? Primary responsibilities include Lead Wayfinder Frontier AI Services customer engagements end-to-end scope the work deliver the technical findings and present results to executive and technical stakeholders. Review and triage findings from our agentic code scanning pipeline against customer C C++ Rust and Java codebases. Validate true positives eliminate noise and ensure every finding that reaches the customer is a decision they can act on. Conduct deep code review across C C++ Rust and Java code and common frameworks. Present findings to stake holders translate technical risk into business impact and map exposures into end-to-end exploitation chains. Author and maintain SAST rule packs that scale across the customer base and partner with our AI/ML engineers to improve our agentic scanning engine. Provide expert remediation guidance to customer development teams and validate fixes through follow-up review. Work closely with our engineering teams to enhance our agentic code scanning pipeline and reduce false positives. Mentor senior AppSec engineers and software-focused threat hunters to elevate team technical standards. Define and refine the service line's core methodologies engagement playbooks and scoping templates. What Skills and Knowledge Will You Bring? Ideal candidates will have 7+ years in application security or product security with a strong software development background. Proven track record translating complex findings into technical and executive-level debriefs. Excellent written and verbal communication is essential. Experience delivering customer-facing or consulting-style engagements end-to-end comfortable in a distributed remote organization. Expert-level of at least two out of four C C++ Rust and Java in the past you've identified and explained vulnerabilities at the framework level not just the application level. Expert-level of at least two out of four C C++ Rust and Java - understanding of vulnerabilities and secure coding methodologies. Mastery of OWASP Top 10 CWE Top 25 and modern authentication infrastructure (SAML OAuth OIDC JWT internals). Experience driving an application through ASVS Level 4 verification. Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines familiarity with AI-assisted code review workflows and validating findings produced by automated and agentic analysis pipelines. Strong threat modeling experience throughout the secure SDLC. Fluency with Git-based source control and CI/CD pipelines including build-pipeline security controls runner hardening and release-gate enforcement. Experience with AI accelerated development / code scanning methodologies. Nice to Have Working depth in Python (Django/Flask) and Node.js (Express) for cross-language reviews. Reverse engineering of compiled C C++ Rust Java (IDA Pro Binary Ninja Ghidra). OSWE CSSLP GWAPT published CVEs or conference talks. Familiarity with SOC 2 ISO 27001 or FedRAMP control mapping. Why SentinelOne? AI is redefining how the world operates and rewriting the rules of security in real time and SentinelOne was built for this moment. From day one we architected an AI-native platform designed to operate at machine speed not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together this is that place. We invest in our Sentinels with comprehensive competitive benefits designed to support you and your family Equity & Rewards Restricted Stock Units (RSUs) Employee Stock Purchase Plan (ESPP) Time Off & Wellbeing Flexible time off Paid company holidays and paid sick time Gender-neutral parental leave Grandparent leave Insurance & Financial Security Medical dental and vision coverage 401(k) retirement plan with company match Life and disability insurance Health and dependent care FSA Voluntary benefits (hospital accident critical illness) Employee Assistance Program (EAP) ARAG pre-paid legal Nationwide pet insurance Cancer Care program Global business travel medical insurance Work Perks & Flexibility Home office allowance Mobile phone reimbursement Wellness & Lifestyle Wellness coach Wellness/gym reimbursement Fertility coverage Adoption & surrogacy reimbursement SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race religion color national origin gender (including pregnancy childbirth or related medical conditions) sexual orientation gender identity gender expression age status as a protected veteran status as an individual with a disability or other applicable legally protected characteristics. SentinelOne participates in the E-Verify Program for all U.S. based roles.

Secure Software Engineer

Sammamish, WA

Secure Software Engineer - Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud AI data and enterprise solutions across the United States. This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential. Job Title Secure Software Engineer Location 100% Remote (U.S.) Position Type Full-time Direct W2 Salary Range $100000–$150000 Annually Experience Required 6+ years Sponsorship U.S. Citizens Green Card Holders EAD Holders and H-1B transfer candidates are encouraged to apply. We are unable to sponsor new H-1B visa petitions for this position. Job Summary We are looking for an Application Security Engineer to embed security throughout the software development lifecycle partnering with engineering teams to design secure systems identify vulnerabilities and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise strong software engineering fundamentals and a track record of shipping security improvements that meaningfully reduce risk in production. Required Qualifications Bachelor’s degree in Computer Science Cybersecurity or a related field. Five or more years of application security or security engineering experience. Strong understanding of OWASP Top 10 common vulnerability classes and modern exploit patterns. Hands-on experience performing code review across at least two major languages. Deep familiarity with SAST DAST SCA and CI/CD-integrated security tooling. Strong understanding of authentication authorization and cryptographic primitives. Experience with cloud security and modern infrastructure controls. Strong communication skills with technical and non-technical audiences. Proficiency in at least one programming language for tooling and automation. Experience working closely with engineering teams in an Agile environment. Preferred Qualifications Industry certifications such as OSCP OSCE GWAPT or CISSP. Experience with offensive security tooling and red-team operations. Bug bounty experience public CVEs or open-source security contributions. Familiarity with AI/LLM application security considerations. Exposure to regulated industries with strict compliance requirements. How to Apply Would you like to know more about this opportunity? For immediate consideration please send your resume to Jenny@bvteck.com or contact us at (908) 505-3544. Learn more about Bright Vision Technologies at www.bvteck.com. Bright Vision Technologies is an Equal Opportunity Employer. Equal Employment Opportunity (EEO) Statement Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race color religion sex sexual orientation gender identity or expression national origin age genetic information disability veteran status or any other protected status as defined by applicable federal state or local laws. This commitment extends to all aspects of employment including recruitment hiring training compensation promotion transfer leaves of absence termination layoffs and recall. BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment. Powered by JazzHR 2P4IST9ruQ

Senior Security Researcher (Red Team)

US Remote United States Remote

Who We Are Pindrop is the Real Human + Right Human® Identity Trust Platform for the AI era. As AI-driven fraud and deepfakes erode trust in digital communication Pindrop delivers continuous identity verification and deepfake detection across voice video and digital interactions in real time. Enterprises rely on Pindrop to secure billions of high-risk customer interactions each year including top U.S. banks as well as leading insurers and healthcare providers. Powered by models trained on more than 1.5 billion real-world interactions annually and protected by 300+ patents Pindrop restores trust while reducing fraud lowering operational costs and improving customer experience. Recognized by TIME as one of the Top 10 Most Influential Software Companies of 2026 and by Inc. for Best in Business for Innovation Pindrop is backed by leading investors including Andreessen Horowitz IVP and CapitalG. What you’ll do As a Senior Security Researcher (Red Team) you will help Pindrop proactively identify and exploit weaknesses across product cloud and AI-powered systems so we can strengthen defenses before adversaries do. This role blends hands-on offensive security GenAI attack simulation security engineering and operational partnership with blue-team product and AI/ML stakeholders. Design and execute red team operations against Pindrop’s GenAI systems LLM pipelines RAG architectures autonomous agents APIs SaaS products and cloud environments simulating real-world attacks across both traditional and AI-specific attack surfaces. Conduct adversarial testing focused on prompt injection indirect prompt attacks jailbreaking model extraction training-data poisoning data leakage inference abuse and unauthorized output manipulation. Use deepfake generation voice synthesis and related spoofing techniques to test and attempt to defeat Pindrop’s voice authentication and deepfake detection capabilities helping identify model robustness and detection gaps. Develop novel attack chains that combine GenAI vulnerabilities with infrastructure application identity and API weaknesses to create realistic end-to-end threat scenarios. Plan and execute full-scope penetration tests and support bug bounty efforts across Pindrop’s web applications APIs SaaS products and AWS/GCP environments using commercial and open-source offensive tooling. Perform architecture reviews security code reviews and threat modeling with emphasis on vulnerabilities introduced by AI/ML components model integrations and LLM-facing services. Build automation for offensive security workflows testing compliance checks alerting and reporting using Python or similar scripting languages including AI-native attack tooling where useful. Partner closely with SecOps and security engineering to improve detections tune response workflows and translate red team findings into practical remediation and defensive improvements. Stay current on GenAI security research adversarial ML techniques evolving threat intelligence and relevant regulatory developments then apply those insights to Pindrop’s security program. Who you are You are an adversarial thinker who approaches security from an attacker’s perspective and brings the creativity rigor and curiosity to prove it. You have genuine hands-on experience attacking AI systems not just reading about them and you enjoy breaking assumptions that others consider safe. You continuously look for automation and AI-powered efficiencies in offensive security workflows. You communicate clearly and can translate technical findings into prioritized actionable guidance for technical and executive audiences alike. You work independently and thrive in ambiguous fast-moving environments with minimal supervision. You are resilient optimistic accountable and adaptable when priorities shift. Your skill-set Must-haves 3+ years of hands-on penetration testing and red team experience across SaaS applications cloud infrastructure APIs and web applications. Demonstrable experience attacking GenAI or LLM-based systems including prompt injection jailbreaking indirect prompt attacks model extraction or adversarial input generation. Hands-on experience with deepfake tools voice synthesis or audio/visual spoofing technologies in an offensive or research context. Strong proficiency with offensive security tooling such as Burp Suite OWASP ZAP Nmap Metasploit Cobalt Strike or equivalent frameworks. Experience configuring and operating SAST and DAST tools and integrating them into CI/CD pipelines. Proficiency in at least one scripting or programming language with Python strongly preferred for custom attack tooling and workflow automation. Familiarity with AI-specialized security tools or frameworks such as Garak PyRIT Claude Security or similar adversarial ML tooling. Strong understanding of cloud security architecture container security API security and common security standards including ISO 27001/27002 NIST CIS PCI DSS OWASP and SOC 2. Nice-to-haves Prior software development or secure architecture experience including the ability to reason about production code across multiple languages. Research publication or deep practitioner background in adversarial machine learning LLM security or voice/audio deepfake detection. Relevant certifications such as OSCP GPEN GWAPT GXPN CEH or equivalent. Prior experience in voice biometrics AI security fraud prevention or similarly high-risk product environments. What’s in it for you As a Pindropper you’ll join a rapidly growing company making technology more human with the power of voice. You’ll help shape how Pindrop attacks and defends modern AI-enabled systems working at the intersection of offensive security GenAI deepfake defense and cloud security. Your work will have direct impact on how we protect voice identity and high-trust customer interactions. You’ll work alongside a passionate high-performing team committed to excellence and enjoying the journey together. What we offer As a part of Pindrop you’ll have a direct impact on our growing list of products and the future of security in the voice-driven economy. We hire great people and take care of them. Here’s a snapshot of the benefits we offer Competitive compensation package including RSUs (Restricted Stock Units) for all employees so everyone shares in our long-term success. Remote-first environment - giving you flexibility and autonomy in how you structure your day. While we work flexibly we prioritize meaningful in-person moments through regular team on-sites company-wide events and intentional gatherings that foster connection collaboration and shared success. Unlimited Paid Time Off (PTO) Generous health and welfare plans to choose from - including one employer-paid “employee-only” plan! Best-in-class Health Savings Account (HSA) employer contribution Low-cost vision and dental plans for you and your family providing comprehensive coverage and peace of mind. Paid Parental Leave - Including birth adoptive & foster parents One year of diaper delivery for your newest addition to the family! It’s our way of welcoming new Pindroplets to the family! Recurring monthly phone and internet allowance to help cover essential connectivity costs and support flexible work. Enhanced fertility and GLP-1 benefits to support family-building journeys and personalized health needs. Annual Learning & Development stipend to support your professional growth skill-building certifications and continued education. LI-Remote Please note that the base pay range is a general guideline only. Pindrop considers factors such as (but not limited to) scope and responsibilities of the position a candidate's work experience education/training and key skills as well as market and business considerations when extending an offer. US Base Pay Range $125000 $165000 USD Not sure if this is you? We want a diverse global team with a broad range of experience and perspectives. If this job sounds great but you’re not sure if you qualify apply anyway! We carefully consider every application and will either move forward with you find another team that might be a better fit keep in touch for future opportunities or thank you for your time. AI - A Transformative Force At Pindrop we view artificial intelligence as a transformative force that when harnessed responsibly can unlock unprecedented value for our customers partners and society and enable and empower us to continue to deliver cutting-edge technology to combat fraud and unblur the lines between what it means to be human versus machine. Pindrop may use AI tools to help prioritize job applications for human review. The AI tool may analyze your work experience and skills to assess fit for the role but does not consider your name or contact details. Applications with the strongest match to job requirements are prioritized for human review not all applications may be individually reviewed. Pindrop is an Equal Opportunity Employer Here at Pindrop it is our mission to create and maintain a diverse and inclusive work environment. As an equal opportunity employer all qualified applicants receive consideration for employment without regard to race color age religion sex gender gender identity or expression sexual orientation national origin genetic information disability marital and/or veteran status.

Penetration Tester

Penetration Tester 6 month contract to perm Fully Remote Duties Execute cloud security assessments across AWS Azure or GCP environments. Identify exploit and document vulnerabilities in a controlled and ethical manner. Validate remediation efforts through structured re-testing. Plan and execute adversary emulation exercises aligned with real-world threat actors. Simulate full attack lifecycles including initial access privilege escalation lateral movement persistence and data exfiltration. Conduct social engineering and phishing campaigns where authorized. Evaluate detection and response capabilities in collaboration with defensive teams. Develop and refine offensive tooling and techniques to emulate evolving threats. Utilize AI and LLM-based tools to enhance reconnaissance payload development and automation. Develop workflows integrating AI into penetration testing processes and Red team operations. Test for vulnerabilities including prompt injection jailbreak attempts model abuse and data leakage. Evaluate risks related to model extraction model inversion and training data poisoning. Assess Retrieval-Augmented Generation (RAG) implementations and AI plugin integrations. Contribute to AI threat modeling and secure deployment recommendations. Qualifications Bachelor’s degree in Cybersecurity Computer Science Information Technology or equivalent experience. 3–7+ years of experience in penetration testing red teaming or offensive security. Offensive security certifications (e.g. OSCP OSEP CRTO GPEN GWAPT). Experience testing AI or machine learning systems in production environments. Experience using AI tools to automate or enhance technical workflows. Understanding of AI/LLM architectures and common attack vectors against AI systems. Demonstrated experience conducting full-scope penetration tests and adversary simulations. Strong understanding of networking operating systems (Windows and Linux) Active Directory and web technologies. Experience with industry-standard tools such as Burp Suite Metasploit Nmap BloodHound and command-and-control frameworks. Proficiency in Python and scripting (Bash or PowerShell).

Manager, Penetration Testing

México, Mexico

About KTSA We are KTSA – KPMG Technology Services Americas. A Service Delivery Center of KPMG US with offices in Mexico City Guadalajara and a growing network of remote talent across the country. We deliver high-value technology consulting and corporate support services to KPMG US and its clients. At KTSA our Employer Value Proposition is clear Explore . Explore isn’t just a word — it’s how we grow lead and thrive. It’s the mindset that drives our culture and shapes every opportunity Experience a collaborative inclusive and multicultural workplace where you belong. Excel by creating impact and leaving your mark on global projects. Expand your potential with real career paths learning programs and mentorship. Express your individuality — come as you are and thrive as your authentic self. Key Responsibilities • Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities control gaps and practical paths to remediation. • Plan and execute penetration testing activities across web applications APIs external and internal networks cloud-hosted environments and supporting infrastructure as applicable to the engagement scope. • Assess common application and API security weaknesses including authentication flaws authorization issues injection vulnerabilities business logic flaws insecure configurations and exposure of sensitive data. • Document findings clearly including business impact technical evidence risk context reproducible steps and practical remediation guidance for member firm stakeholders. • Facilitate security assessments and support the resolution of identified vulnerabilities through clear communication retesting and coordination with application infrastructure and security teams. • Communicate assessment results to technical and non-technical stakeholders through written reports walkthroughs and remediation discussions. • Stay current with common and emerging security threats penetration testing techniques tooling and assessment methodologies relevant to application and network security. Qualifications • Bachelor’s degree with 5+ years of practical experience in cybersecurity focused on application penetration testing network penetration testing and related cloud security assessment activities. • Strong hands-on experience performing manual web application API network and infrastructure penetration testing including validation beyond automated scanning tools. • Strong familiarity with frameworks and methodologies such as MITRE ATT&CK OWASP Top 10 OWASP API Security Top 10 PTES. • Relevant certifications such as OSCP GPEN GWAPT OSCE GXPN or similar are highly preferred. CISSP and Azure or other cloud platform certifications are a plus. • Solid foundation in network application and cloud security concepts with hands-on experience identifying validating and explaining vulnerabilities in real-world environments. • Proficiency in scripting and automation with experience in Python Bash or PowerShell. • Experience with common and emerging security threats scanning tools exploitation techniques assessment methodologies and secure remediation practices. • Demonstrated understanding of security principles IT security controls and related technologies and products. • Strong verbal and written communication problem solving analytical and independent judgment skills to support an environment driven by customer service collaboration and teamwork. • Experience working directly with clients project stakeholders or business units to clarify scope communicate findings and support remediation efforts. And because we know that thriving at work also means thriving in life we back this mindset with KTSAMÁS our total rewards program designed to support your well-being goals and personal milestones. Expand your possibilities with KTSA through KTSAMÁS where you can access Extended maternity paternity and adoption leaves Above-market vacation benefits Hybrid work model Learning opportunities training and certification programs Extended marriage leave and daycare support Wellness and Employee Assistance Programs (EAP) Comprehensive medical plan life insurance car insurance and funeral assistance Visit www.ktsa.com.mx to learn more. At KTSA we celebrate and support everyone’s individuality. We do not discriminate against any race religion color national origin gender sexual orientation gender identity or expression age marital status or disability. We are supportive of helping you to achieve a balance between your home and work demands. We are happy to discuss specific requirements and our range of flexible working arrangements could be of interest. Please ask to find out more. We strongly state that we DO NOT require a certificate of non-pregnancy or HIV in order to participate in any of our processes. Explore KTSA we dare to be different! Home - KTSA KTSA - KPMG Technology Services of Americas

unlock: sign-up for free / login and use the searches from your home page
🔥 job listings updated in real time


For the 10 positions listed above we've analyzed the salary ranges, where available, and the resulting overall salary range is: 90K - 215K USD.

For 7 similar GWAPT position(s) we've listed yesterday we've checked the salary ranges, as posted, and the resulting overall range is: 90K - 215K USD.

For 132 similar GWAPT position(s) we've listed in the previous 30 days we've processed the salary ranges data as posted by employers in job descriptions and the resulting overall range is: 70K - 216.9K USD.

View highest-paying job

Note: If any discrepancies or 'wild' numbers appear this could be because of: typos in job postings, data source errors, ghost jobs, etc. We do not modify salary data inserted in JDs by employers nor use estimates.


Login & search by other job titles, a specific location or any keyword.
Additional custom search filters are available once you login.