Search 38 Remote eJPT Jobs

38 remote jobs

Counter-Threat Intelligence Engineer

Remote United States

Job Overview Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify understand and counter cyber threats that could impact our learners educators associates platforms data and business operations. This role combines threat intelligence ethical hacking exposure validation adversary emulation and security engineering to turn emerging threat information into actionable defenses. The engineer will work closely with Security Operations IT Operations Risk Legal Compliance Product Engineering and business stakeholders to help reduce attack surface improve detection logic support incident response and translate technical findings into clear recommendations. The ideal candidate brings hands-on offensive security experience exceptional analytical judgment and the ability to communicate threat context in a way that drives practical remediation and measurable risk reduction. Job Responsibilities Collect analyze and operationalize strategic tactical and operational threat intelligence from trusted internal and external sources including indicators of compromise adversary tactics techniques and procedures emerging vulnerabilities and targeted threat activity. Perform adversary-focused research and ethical hacking activities with authorization to validate exposures identify likely attack paths and recommend defensive improvements across endpoints cloud services applications identity platforms networks and third-party integrations. Partner with Security Operations to create tune and validate detections playbooks threat hunting hypotheses and response workflows in data log pipelines SIEM XDR EDR vulnerability management and related security tools. Support Continuous Threat Exposure Management efforts by helping scope assets discover exposures prioritize findings based on business risk validate exploitability and coordinate mobilization of remediation activities with IT infrastructure engineering and business owners. Produce concise actionable threat intelligence reports briefings and technical recommendations for audiences ranging from security analysts to senior leadership emphasizing relevance impact urgency and practical next steps. Contribute to incident response investigations by enriching alerts with threat context malware or phishing analysis infrastructure research attack timeline reconstruction and lessons learned. Maintain awareness of threat actor tradecraft vulnerability exploitation trends cloud and identity attacks education-sector threats data protection risks and changes in attacker use of automation and artificial intelligence. Use independent judgment to make recommendations on defensive priorities detection improvements risk acceptance considerations and escalation paths while staying aligned with Cambium policies standards and governance expectations. Job Requirements 5+ years of progressive cybersecurity experience with at least 2 years in threat intelligence ethical hacking penetration testing detection engineering security operations incident response vulnerability management or a closely related role. Certified Ethical Hacker (CEH) certification is highly preferred similar hands-on offensive security or threat intelligence certifications may be considered such as OSCP GPEN CompTIA PenTest+ CPENT eJPT GCTI CTIA or equivalent practical experience. Proven working knowledge of the cyber kill chain MITRE ATT&CK common attack techniques malware and phishing behaviors cloud and identity threats vulnerability exploitation attacker infrastructure and defensive countermeasures. Hands-on experience with security tools and data sources such as SIEM XDR/EDR vulnerability scanners threat intelligence platforms cloud security tools identity logs endpoint telemetry network telemetry and ticketing/workflow platforms. Ability to write clear threat intelligence summaries detection recommendations executive briefings remediation guidance and technical documentation that can be acted on by cross-functional teams. Experience conducting authorized security testing adversary emulation attack surface analysis detection validation or threat hunts in a disciplined evidence-based and policy-aligned manner. Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering or a related field preferred equivalent professional experience and certifications may be considered. High judgment strong ethics discretion with sensitive information collaborative communication style and commitment to protecting confidential proprietary student customer associate and business data. Preferred Qualifications Experience in education technology SaaS cloud-first remote-first or regulated environments. Experience building threat hunting content Sigma/YARA rules KQL/SPL queries detection-as-code or automation for enrichment and triage. Familiarity with scripting or automation using Python PowerShell Bash APIs or SOAR-style workflows. Working knowledge of data privacy secure software development third-party risk and compliance frameworks such as ISO 27001 SOC 2 NIST CSF or NIST SP 800-series guidance. To learn more about our organization and the exciting work we do visit www.cambiumlearning.com Remote First Work Environment Our Remote First approach gives employees the flexibility and trust they need to effectively balance work with life. It creates a culture in which all employees are valued and where success is measured in results. It allows us to work collaboratively inclusively and for greater positive impact regardless of our individual locations. If you will be working remotely either occasionally or on a permanent basis you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload. The successful candidate will be expected to actively participate in video-based interviews during the recruiting process and ongoing virtual meetings with their camera on as part of their role. To maintain confidentiality and ensure a fair evaluation process the use of note-taking tools reference materials or AI-powered tools (including generative AI language models or similar technologies) during interviews or other selection activities is prohibited unless prior written approval has been obtained from the People Experience team. If you require an exception for medical accessibility or other reasons please contact your Talent Acquisition team member to discuss accommodations in advance. As part of our Remote-First benefits Cambium offers reimbursement to help cover the cost of setting up your home or remote office. An Equal Opportunity Employer We are dedicated to fostering a culture that celebrates unique backgrounds ideas and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race color age religion sex (including pregnancy gender gender identity/expression or sexual orientation) national origin protected veteran status disability or genetic information (including family medical history). We will provide reasonable accommodations for qualified individuals with disabilities. You may request an accommodation during the recruiting process with your Talent Acquisition team member.

Ethical Hacker / Cybersecurity Specialist

Kathmandu, Bāgmatī, Nepal

Location  Nepal / Remote Employment Type  Full-time Company  Nepal AI Labs About Nepal AI Labs Nepal AI Labs is building AI-powered products and technology platforms designed to solve real-world problems in Nepal and beyond. As we build and scale security and responsible technology are core to everything we do. We are looking for an  Ethical Hacker / Cybersecurity Specialist  who can think like an attacker work like a defender and help us build more secure products from the ground up. Role As an Ethical Hacker you will be responsible for identifying testing and helping remediate security vulnerabilities across our web applications APIs infrastructure and AI-powered products. You will conduct authorized security assessments penetration testing vulnerability research and security reviews of our own systems. Your goal will not simply be to find vulnerabilities but to help our engineering team understand and fix them before they can be exploited. What you'll do Conduct authorized penetration testing of web applications APIs mobile applications and infrastructure. Identify and exploit security vulnerabilities in a controlled environment. Perform vulnerability assessments and security audits across our products and platforms. Test authentication authorization session management access controls APIs databases and other critical components. Identify common and advanced vulnerabilities including OWASP Top 10 risks. Perform reconnaissance threat modeling and attack-surface analysis. Assess cloud infrastructure network security and deployment environments. Test AI/ML applications for security risks such as prompt injection data leakage insecure tool use and model-related vulnerabilities. Conduct security testing during product development and before major releases. Document vulnerabilities with clear reproduction steps impact severity and recommended remediation. Work closely with developers and engineers to validate fixes and improve security practices. Stay updated on emerging vulnerabilities attack techniques CVEs and cybersecurity research. Help establish internal security testing methodologies and responsible disclosure practices. What we are looking for Strong understanding of cybersecurity principles and offensive security methodologies. Hands-on experience with penetration testing and vulnerability assessment. Good understanding of  OWASP Top 10 API Security authentication authorization and web security . Familiarity with tools such as Burp Suite Nmap Metasploit Wireshark Kali Linux or equivalent tools. Knowledge of networking Linux HTTP/HTTPS DNS TCP/IP databases and common web technologies. Ability to understand source code and identify security issues in applications. Familiarity with cloud security and modern deployment environments is a plus. Interest or experience in  AI security / LLM security  is highly desirable. Strong analytical and problem-solving skills. Ability to communicate technical vulnerabilities clearly to both technical and non-technical teams. A responsible and ethical approach to security testing. Good to Have O SCP CEH eJPT PNPT Security+ or equivalent practical experience. Experience with bug bounty programs or responsible vulnerability disclosure. Experience testing REST/GraphQL APIs. Knowledge of Docker Kubernetes AWS Azure or GCP security. Experience with Python Bash JavaScript or other scripting/programming languages. Familiarity with OWASP ASVS WSTG API Security Top 10 or MITRE ATT&CK. Experience with AI red teaming LLM security or adversarial testing. Important This role involves  authorized security testing only . All testing will be conducted against systems applications and infrastructure owned or explicitly authorized by Nepal AI Labs. We are looking for someone who sees ethical hacking not as breaking things but as  f inding weaknesses before someone else does. Why Join Nepal AI Labs Work directly on real-world AI and technology products. Take ownership of cybersecurity across products from the early stages. Work closely with engineers and product teams. Explore the emerging field of  AI security and LLM security . Help build secure technology originating from Nepal with global ambitions. Opportunity to shape our internal security culture and practices. How to Apply If you are curious technically strong and passionate about breaking systems so they can be made stronger we’d love to hear from you. Apply with your CV and if available links to your GitHub security research bug bounty profile CTF achievements or other relevant work. Here is our email hello@nepalailabs.com. If we don't reply just hack us and let us know

Penetration Tester

Herndon, VA

Job Number R0236401 Penetration Tester The Opportunity Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks develop exploits and engineer attack methodologies. Apply advanced advising skills extensive technical expertise and full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction and mentor and supervise team members as needed. You Have 3+ years of experience with cyber penetration testing or developing risk and threat mitigation plans 3+ years of experience operating in Linux Windows and virtual platforms 3+ years of experience with computer attack methods and system exploitation techniques 3+ years of experience leveraging adversarial tactics to conduct hands-on security testing 3+ years of experience performing network security analysis including software or traffic analysis TS/SCI clearance with a polygraph HS diploma or GED Nice If You Have Experience manually auditing source code including Java Ruby Python JavaScript Rust or C to find security issues Knowledge of tools tactics and techniques targeting Artificial Intelligence (AI) systems and their ecosystems Bachelor's degree in CS Information Systems Engineering or a related field Offensive Security Certified Professional (OSCP) HTB Certified Penetration Tester Specialist (CPTS) eLearnSecurity Junior Penetration Tester (EJPT) GIAC Global Information Assurance Penetration Tester (GPEN) or GIAC Cloud Penetration Tester Certification Clearance Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information TS/SCI clearance with polygraph is required. Compensation At Booz Allen we celebrate your contributions provide you with opportunities and choices and support your total well-being. Our offerings include health life disability financial and retirement benefits as well as paid leave professional development tuition assistance work-life programs and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors including but not limited to location the individual’s particular combination of education knowledge skills competencies and experience as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86800.00 to $198000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen and we are committed to the responsible and ethical use of AI tools. However we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided . Work Model Our people-first culture prioritizes the benefits of collaboration whether it occurs in person or virtually. To support engagement and effective communication employees working virtually are generally expected to have their cameras on during meetings. Remote If this position is listed as remote there may still be occasions when you are required to work in person at a Booz Allen or customer facility. Hybrid If this position is listed as hybrid you will be expected to work from a Booz Allen facility frequently in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. Onsite If this position is listed as onsite work will primarily be performed at a Booz Allen office or customer facility where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability status as a protected veteran or any other status protected by applicable federal state local or international law.

Vulnerability Management Analyst

North - Remote North is seeking a detail-oriented Vulnerability Management Analyst to join our Cybersecurity team. In this role you will help protect our payment processing platform cloud environments and internal infrastructure by identifying analyzing and prioritizing technical vulnerabilities. Working closely with engineering cloud infrastructure and IT teams you will leverage enterprise security tools (such as Wiz and Tenable) to track risk and diplomatically advocate for timely remediation. This role is ideal for an early-to-mid career cybersecurity professional with strong analytical and interpersonal skills who enjoys turning security data into actionable fixes. What you'll do Vulnerability Identification & Scanning Operate maintain and assist in configuring scanning platforms (Wiz Tenable) across cloud assets containers data centers network infrastructure and endpoints. Analysis & Prioritization Review vulnerability data reduce false positives and prioritize risks based on business context CVSS scores threat intelligence and payment industry risk factors. Remediation Advocacy Act as a liaison to engineering IT and operations teams to champion patching initiatives explain technical risks and follow up on overdue SLAs. Tracking & Metrics Track remediation progress communicate risk posture to leadership and maintain dashboards reports and key performance indicators (KPIs). Compliance Support Support security audit and compliance efforts (such as PCI-DSS) by providing evidence of regular vulnerability scanning and remediation. Continuous Improvement Refine vulnerability management processes playbooks and automated workflows to reduce exposure windows. What we need from you Education And Experience Bachelor’s degree in Cybersecurity Computer Science Information Technology or a related technical field (or equivalent practical experience). 3 years of hands-on experience in cybersecurity IT system administration or risk management. Hands-on experience operating enterprise scanning platforms specifically Wiz and Tenable. Knowledge Skills & Abilities Core Vulnerability Concepts Solid understanding of the vulnerability management lifecycle Common Vulnerabilities and Exposures (CVEs) CVSS scoring and common attack vectors and vulnerability exploitation. Tooling Familiarity Exposure to enterprise scanner technologies (Tenable) and cloud security/exposure management tools (Wiz). Analytical Mindset Ability to analyze large datasets of vulnerability scans identify trends and translate raw data into clear actionable reporting. Interpersonal & Communication Skills Excellent verbal and written communication skills while building relationships across teams and encouraging patch completion. Technical Foundations Understanding of core OS concepts (Windows Linux) cloud security fundamentals (AWS Azure or GCP) and enterprise networking. How to stand out (Preferred) 5 years of relevant or hands-on experience in cybersecurity IT system administration or risk management Experience within fintech payment processing or another highly regulated fast-paced environment. Familiarity with payment industry standards and security frameworks (PCI-DSS NIST Cybersecurity Framework CIS Benchmarks). Experience using ticketing and project tracking tools such as Jira to track vulnerability work items. Basic scripting knowledge (Python PowerShell Bash or API queries) to automate reporting or routine tasks. Certifications such as CompTIA Security+ Network+ or eJPT are a plus but not required. Salary range $70000-$110000 Pay within this range varies by work location and on job-related knowledge skills and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process. Please note North is a US based company and no sponsorship is available for this position at this time. Who we are North and our family of companies are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company we provide everything business owners need to get paid whether they serve customers in a physical storefront online or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning hands-on approach to personal service that our merchants won’t find anywhere else. Let’s go North together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. At North we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer. To learn more about North and our family of companies visit our website north.com

Counter-Threat Intelligence Engineer

Job Overview Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify understand and counter cyber threats that could impact our learners educators associates platforms data and business operations. This role combines threat intelligence ethical hacking exposure validation adversary emulation and security engineering to turn emerging threat information into actionable defenses. The engineer will work closely with Security Operations IT Operations Risk Legal Compliance Product Engineering and business stakeholders to help reduce attack surface improve detection logic support incident response and translate technical findings into clear recommendations. The ideal candidate brings hands-on offensive security experience exceptional analytical judgment and the ability to communicate threat context in a way that drives practical remediation and measurable risk reduction. Job Responsibilities Collect analyze and operationalize strategic tactical and operational threat intelligence from trusted internal and external sources including indicators of compromise adversary tactics techniques and procedures emerging vulnerabilities and targeted threat activity. Perform adversary-focused research and ethical hacking activities with authorization to validate exposures identify likely attack paths and recommend defensive improvements across endpoints cloud services applications identity platforms networks and third-party integrations. Partner with Security Operations to create tune and validate detections playbooks threat hunting hypotheses and response workflows in data log pipelines SIEM XDR EDR vulnerability management and related security tools. Support Continuous Threat Exposure Management efforts by helping scope assets discover exposures prioritize findings based on business risk validate exploitability and coordinate mobilization of remediation activities with IT infrastructure engineering and business owners. Produce concise actionable threat intelligence reports briefings and technical recommendations for audiences ranging from security analysts to senior leadership emphasizing relevance impact urgency and practical next steps. Contribute to incident response investigations by enriching alerts with threat context malware or phishing analysis infrastructure research attack timeline reconstruction and lessons learned. Maintain awareness of threat actor tradecraft vulnerability exploitation trends cloud and identity attacks education-sector threats data protection risks and changes in attacker use of automation and artificial intelligence. Use independent judgment to make recommendations on defensive priorities detection improvements risk acceptance considerations and escalation paths while staying aligned with Cambium policies standards and governance expectations. Job Requirements 5+ years of progressive cybersecurity experience with at least 2 years in threat intelligence ethical hacking penetration testing detection engineering security operations incident response vulnerability management or a closely related role. Certified Ethical Hacker (CEH) certification is highly preferred similar hands-on offensive security or threat intelligence certifications may be considered such as OSCP GPEN CompTIA PenTest+ CPENT eJPT GCTI CTIA or equivalent practical experience. Proven working knowledge of the cyber kill chain MITRE ATT&CK common attack techniques malware and phishing behaviors cloud and identity threats vulnerability exploitation attacker infrastructure and defensive countermeasures. Hands-on experience with security tools and data sources such as SIEM XDR/EDR vulnerability scanners threat intelligence platforms cloud security tools identity logs endpoint telemetry network telemetry and ticketing/workflow platforms. Ability to write clear threat intelligence summaries detection recommendations executive briefings remediation guidance and technical documentation that can be acted on by cross-functional teams. Experience conducting authorized security testing adversary emulation attack surface analysis detection validation or threat hunts in a disciplined evidence-based and policy-aligned manner. Bachelor’s degree in Cybersecurity Computer Science Information Technology Engineering or a related field preferred equivalent professional experience and certifications may be considered. High judgment strong ethics discretion with sensitive information collaborative communication style and commitment to protecting confidential proprietary student customer associate and business data. Preferred Qualifications Experience in education technology SaaS cloud-first remote-first or regulated environments. Experience building threat hunting content Sigma/YARA rules KQL/SPL queries detection-as-code or automation for enrichment and triage. Familiarity with scripting or automation using Python PowerShell Bash APIs or SOAR-style workflows. Working knowledge of data privacy secure software development third-party risk and compliance frameworks such as ISO 27001 SOC 2 NIST CSF or NIST SP 800-series guidance. To learn more about our organization and the exciting work we do visit www.cambiumlearning.com Remote First Work Environment Our Remote First approach gives employees the flexibility and trust they need to effectively balance work with life. It creates a culture in which all employees are valued and where success is measured in results. It allows us to work collaboratively inclusively and for greater positive impact regardless of our individual locations. If you will be working remotely either occasionally or on a permanent basis you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload. The successful candidate will be expected to actively participate in video-based interviews during the recruiting process and ongoing virtual meetings with their camera on as part of their role. To maintain confidentiality and ensure a fair evaluation process the use of note-taking tools reference materials or AI-powered tools (including generative AI language models or similar technologies) during interviews or other selection activities is prohibited unless prior written approval has been obtained from the People Experience team. If you require an exception for medical accessibility or other reasons please contact your Talent Acquisition team member to discuss accommodations in advance. As part of our Remote-First benefits Cambium offers reimbursement to help cover the cost of setting up your home or remote office. An Equal Opportunity Employer We are dedicated to fostering a culture that celebrates unique backgrounds ideas and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race color age religion sex (including pregnancy gender gender identity/expression or sexual orientation) national origin protected veteran status disability or genetic information (including family medical history). We will provide reasonable accommodations for qualified individuals with disabilities. You may request an accommodation during the recruiting process with your Talent Acquisition team member.

Penetration Tester

Herndon, VA

Job Number R0247922 Penetration Tester The Opportunity Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks develop exploits and engineer attack methodologies. Apply advanced advising skills extensive technical expertise and full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction and mentor and supervise team members as needed. You Have 3+ years of experience with cyber penetration testing or developing risk and threat mitigation plans 3+ years of experience operating in Linux Windows and virtual platforms 3+ years of experience with computer attack methods and system exploitation techniques 3+ years of experience leveraging adversarial tactics to conduct hands-on security testing 3+ years of experience performing network security analysis including software or traffic analysis TS/SCI clearance with a polygraph HS diploma or GED Nice If You Have Experience manually auditing source code including Java Ruby Python JavaScript Rust or C to find security issues Knowledge of tools tactics and techniques targeting Artificial Intelligence (AI) systems and their ecosystems Bachelor's degree in CS Information Systems Engineering or a related field Offensive Security Certified Professional (OSCP) HTB Certified Penetration Tester Specialist (CPTS) eLearnSecurity Junior Penetration Tester (EJPT) GIAC Global Information Assurance Penetration Tester (GPEN) or GIAC Cloud Penetration Tester Certification Clearance Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information TS/SCI clearance with polygraph is required. Compensation At Booz Allen we celebrate your contributions provide you with opportunities and choices and support your total well-being. Our offerings include health life disability financial and retirement benefits as well as paid leave professional development tuition assistance work-life programs and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors including but not limited to location the individual’s particular combination of education knowledge skills competencies and experience as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86800.00 to $198000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen and we are committed to the responsible and ethical use of AI tools. However we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided . Work Model Our people-first culture prioritizes the benefits of collaboration whether it occurs in person or virtually. To support engagement and effective communication employees working virtually are generally expected to have their cameras on during meetings. Remote If this position is listed as remote there may still be occasions when you are required to work in person at a Booz Allen or customer facility. Hybrid If this position is listed as hybrid you will be expected to work from a Booz Allen facility frequently in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. Onsite If this position is listed as onsite work will primarily be performed at a Booz Allen office or customer facility where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability status as a protected veteran or any other status protected by applicable federal state local or international law.

Information Security Consultant

Navi Mumbai, Maharashtra, India

Position Information Security Consultant Location Navi Mumbai India Shift Timings General Company Profile Tinycrows Private Limited is a budding cybersecurity firm working with BFSI fintech and technology-driven enterprises dedicated to helping these businesses protect their digital assets and mitigate risks. At Tinycrows we follow a 'shift left' cybersecurity approach to fortify the security of products. Our team of trusted professionals with experience from top consulting firms like Microsoft and Deloitte design robust security solutions for various industries. We have a proven track record of implementing cybersecurity best practices for startups and large organizations ensuring digital assets remain secure in today's threat landscape. Role Description Tinycrows has designed this role for a highly motivated and technically adept individual with strong expertise in Threat Intelligence Web and Mobile (iOS/Android) Application Penetration Testing . This role requires analysing designing and implementing robust security to help the stakeholders maintain and strengthen their security posture. An ideal fit for this position is an individual who is passionate about offensive security with a hands-on approach to identifying vulnerabilities supporting secure development and contributing to scalable AppSec initiatives. Exposure to Red Team operations Active Directory attack paths and cloud environments is a strong plus. The Consultant will work closely with clients to ensure the security of their digital assets. Key Responsibilities Execute in-depth security assessments and Manual penetration testing of web and mobile applications. Perform secure code reviews to identify flaws across various tech stacks (e.g. JavaScript Java/Kotlin Swift Python). Contribute to the automation and enhancement of internal testing frameworks reporting tools and reusable AppSec methodologies. Leverage tools such as Burp Suite Pro nmap slmap MobSF Frida Objection Jadx APKTool and others as part of testing workflows. Collaborate cross-functionally with developers DevOps and product teams to embed security across the SDLC. Support and guidance to CISO CIO and Product Team functions providing security reviews for prospective products and services. Transfer of residual risks to the business/customer as required by the Client’s risk management framework. Collaboration with stakeholder and IT teams to support incident response and investigations using their knowledge of the technology systems sharing security insights. Seek out build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives using influencing and negotiating skills to achieve outcomes. Support Red Teaming engagements including reconnaissance initial access and Active Directory exploitation techniques (e.g. Kerberoasting ACL abuse lateral movement). Deliver detailed technical findings and clear actionable remediation guidance to both technical and non-technical stakeholders. Key Skills Practical experience in web and mobile application security testing including real-world vulnerability exploitation and security implementation. Proficiency with offensive security tools such as Burp Suite Pro nmap sqlmap MobSF Frida etc. Understanding of common vulnerabilities and standards (e.g. OWASP Top 10 CWE MITRE ATT&CK). Understanding of threat intelligence concepts threat actor landscape TTPs IOCs and their application in identifying and assessing cybersecurity risks. Basic experience with cloud security reviews particularly for AWS Azure or GCP-hosted environments. Familiarity with secure development practices modern CI/CD pipelines and DevSecOps integration. Excellent verbal and written communication skills with the ability to clearly explain technical findings to diverse audiences. Comfortable working independently in a fast-paced highly technical environment. Excellent written and verbal communication skills along with the ability to work independently and remotely Current with the evolving threat landscape emerging tools and industry best practices in application security. Preferred Qualifications Formal Cyber Security qualification e.g. Degree/master’s or a well-recognized certification. Exposure to Red Teaming techniques Active Directory attack paths and post-exploitation tooling (e.g. BloodHound Rubeus SharpHound). Experience developing custom scripts or payloads using Python Bash or PowerShell . Familiarity with SAST/DAST tools and API security testing methodologies. Preferred Certifications Industry certifications such as CRTP eMAPT eJPT are a strong plus Perks of Joining Tinycrows If you value growth ownership and learning over just stability and routine we can be the perfect place for you because at Tinycrows we deal with real problems fast pivots and innovation. You learn by doing not just following manuals and your work directly shapes the company’s success and culture. You’re not “just a cog in the wheel”. You get exposure to latest technologies regulatory frameworks and client-facing challenges. You get more autonomy creativity and ownership of projects apart from this you also get Opportunity to be part of the core founding team and contribute to building security from the ground up. Close collaboration with founders and key stakeholders (CISOs CTOs engineering leaders) ensuring your work directly influences strategic decisions. Fast-paced agile environment where innovation and curiosity are encouraged. End-to-end ownership of security assessments tooling and strategy. Steep learning curve with exposure to a wide variety of technologies and attack surfaces. Great opportunities to expand your role and accelerate your career path. Collaborative team culture with support for skill-building and certifications. Opportunities to develop new skills and progress your career. The freedom and flexibility to handle your role in a way that’s right for you. This role requires the individual to work at the client’s site. Therefore working days hours and holidays will be defined by the client. Our People & Culture Our inclusive culture empowers our people to be who they are contribute their unique perspectives and make a difference individually and collectively. It enables us to leverage different ways of thinking ideas and perspectives and bring more creativity and innovation to help solve our clients’ most complex challenges.

Associate Security Research Engineer

Ankara, Turkey

Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so read on!   About Picus Picus Security the leading exposure validation company proves what attackers can exploit and what your defenses stop then closes real gaps with ready-to-deploy fixes and revalidates to confirm at the machine speed that today’s AI threats demand. The Picus Platform spans Picus Autonomous Penetration Testing Picus Breach and Attack Simulation and Picus Exposure Validation unified by Picus Swarm a swarm of AI agents that runs the whole validation loop continuously with human oversight. With 75+ integrations it reaches across on-prem hybrid cloud and endpoint environments.Trusted by many Fortune 500 enterprises Picus was named a 2025 Gartner Peer Insights Customers’ Choice for Adversarial Exposure Validation and is recognized as an Innovation Leader in the Frost Radar for Automated Security Validation.About Role We're growing our Technical Marketing Team to support the high growth and global expansion plans of Picus and we're opening the door for someone at the start of their research-and-content career. In this role you'll learn to go deep on real-world threats and turn that research into technical content that shows the market what Picus can actually do including research papers offensive and defensive security reports whitepapers blogs solution and integration briefs battlecards webinars demos and conference presentations. It's a role built for growth in two directions at once you'll start building your own name in the security community through published work and hands-on research while contributing to how the market understands the category. Our research is regularly picked up and cited by the wider community from major news organizations like Reuters the Associated Press and Forbes to specialist security outlets including Dark Reading BleepingComputer Infosecurity Magazine SCWorld and Help Net Security as well as community platforms like Hacker News. Our work has also been referenced by industry authorities such as MITRE ATT&CK and Gartner and cited in high-impact academic journals. As you grow into the role there will be opportunities to take your work on stage at industry conferences such as Black Hat and GovWare and at local meetups and user groups. You'll be constantly challenged to develop your knowledge and skills in cybersecurity and share what you learn with the world doing meaningful research for a fast-growing cybersecurity company. Are you an early-career SOC analyst junior security consultant aspiring threat hunter security engineer or red/blue/purple team member looking to move into a more research- and publication-focused path? Are you a recent graduate career-changer home-lab tinkerer or CTF player who already writes shares or wants to start? Then this role is for you. This position is based in our Ankara office and follows a hybrid work model. ➡ What You’ll Do ➡ Continuously research emerging threats malware threat actors and vulnerability exploitation campaigns and turn your findings into timely insightful content Contribute to technical content across blogs whitepapers demos solution and integration briefs offensive and defensive research reports and research papers developing your voice and building a strong portfolio along the way Develop a deep understanding of the Picus platform and collaborate with Picus Labs Product and Engineering to translate new capabilities into clear compelling technical narratives Monitor market trends analyst perspectives category leaders emerging product categories and the competitive landscape helping the team turn these insights into differentiated technical content Learn how technical content drives discoverability across search and AI answer engines through SEO and AEO and how it supports audiences throughout the funnel from awareness to purchase Collaborate with Growth Threat Research Red and Blue Teams and Alliances to transform research technical findings and integrations into public-facing content that reaches and resonates with the market. What You Have ➡ 1–2 years of experience (including internships labs CTFs or academic/personal projects) in offensive and/or defensive cybersecurity with a foundational understanding of the security/threat landscape Some technical writing or a genuine eagerness to build a portfolio of published content or projects (blogs notes write-ups talks or research) An ability or strong willingness to develop the ability to translate technical concepts for different audiences Strong proficiency in written and verbal English Curiosity and a drive to keep learning in a fast-moving field Exposure to penetration testing tooling vulnerability management or security control validation and some hands-on familiarity with blue-team tooling such as SIEM or EDR/XDR (lab coursework or work experience all count) Interest in autonomous/agentic security validation (an emerging area exploration counts fully) Early hands-on experience with adversarial techniques (home lab CTF or coursework all count) Basic scripting or automation skills (Python n8n or comparable agent/workflow tooling) Awareness of modern security problems Any contribution to the cybersecurity community however small (blog GitHub forum meetup) Any exposure to public speaking or presenting Cybersecurity-related certifications including entry-level ones (Security+ eJPT BTL1 or similar OSCP/CISSP-level not expected but a plus) Awareness of SEO/AEO principles or content strategy. ➡ Working at Picus Fascinating work - a chance to shape and lead an exciting fast-growing cyber security segment. Security Validation is a concept that helps organizations evaluate their security posture in a continuous automated and repeatable way. This approach allows for the identification of imminent threats provides recommended actions and produces valuable metrics about cyber-risk levels.   Unlimited opportunity! We are growing. At Picus you'll be provided with as much responsibility as you can handle - new career development opportunities constantly arise given our rate of growth.   Global exposure - Get a lot of experience working not only in a fast-growing startup but also interact with customers all around the world.   Be part of a global remote team who is taking on Exposure Validation and a growing market segment.     We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to age sex race color national origin religious belief gender or gender reassignment sexual orientation marriage or civil partnership pregnancy and maternity disability protected veteran status or any other characteristic protected by International law.  Upon conditional offer of employment candidates are required to complete reference and identity checks in line with local labor laws and as per the Company’s employment policy.

Senior Penetration Tester

Ahmedabad, Gujarat, India

Apphaz Security Solutions is a cybersecurity company helping organizations identify manage and reduce their security risks. We work across Penetration Testing VAPT Red Teaming Vulnerability Management and Managed Security Services supporting clients across industries with practical outcome-driven security assessments. We are growing our offensive security team and are looking for a Senior Penetration Tester who enjoys working on real-world security challenges and client engagements. Responsibilities Perform web application API mobile and network penetration testing. Identify and validate security vulnerabilities. Conduct VAPT and security assessments for clients. Prepare clear technical reports and remediation recommendations. Work closely with clients and internal security teams. Support Red Team / Purple Team engagements when required. Qualifications 5+ years of experience in penetration testing / VAPT. Strong knowledge of OWASP Top 10 API security and common vulnerabilities. Hands-on experience with tools such as Burp Suite Nmap and similar security tools. Strong understanding of networking web applications and authentication mechanisms. Good communication and report-writing skills. Relevant certifications such as OSCP CEH eJPT or equivalent are a plus. Travel to client locations will be mandatory with up to 50% travel depending on project requirements. Location Remote If you are passionate about offensive security and enjoy solving real-world security problems we would love to hear from you.

Offensive Security Engineer, Penetration Testing

Warsaw, Mazowieckie, Poland

"Job Location WARSAW PLANT & GO Job Description Are you a person who is passionate about breaking applications devices services and/or processes to help protect them against the worlds most advanced cyber security adversaries? The Information Security Protect organization at Procter & Gamble is responsible for providing a realistic depiction of threat actor behaviors and scenarios during simulated exercises. We drive improvements to applications and systems as well as detection and response capabilities through regular testing of security controls across the enterprise. Responsibilities Lead defined-scope penetration tests across assigned areas such as websites services APIs infrastructure cloud environments networks IoT devices mobile applications and enterprise applications. Partner with Intake Management senior testers and stakeholders to confirm objectives access rules of engagement test assumptions and engagement readiness. Execute testing activities including reconnaissance vulnerability discovery exploitation evidence collection reporting and remediation validation. Identify validate exploit and clearly document security vulnerabilities while operating safely within approved scope. Validate related vulnerabilities together where appropriate to demonstrate realistic impact within the boundaries of the engagement escalating complex attack chains as needed. Test for control gaps where relevant and document observed weaknesses in preventative or detective controls. Investigate and validate Vulnerability Disclosure Program and Bug Bounty findings escalating complex or high-impact issues as needed. Work with engineering product cloud infrastructure and security teams to explain findings and support practical remediation. Use approved scripts templates automation and AI-assisted workflows to support testing efficiency triage reporting and remediation validation. Assist with testing AI-enabled applications and integrations for common risks such as prompt injection sensitive data exposure insecure tool use and authorization flaws. Produce clear standardized reports with reproduction steps evidence impact affected systems and remediation guidance. Contribute to team knowledge sharing documentation test notes templates and process feedback. Job Qualifications Qualifications (Required) Bachelor’s degree or equivalent Polish higher education qualification in Information Security Cybersecurity Computer Science or a related field OR 2+ years of relevant experience in lieu of a degree. 2+ years of experience in penetration testing application security testing vulnerability validation offensive security or related security work. Ability to lead defined-scope penetration tests manage day-to-day execution document results clearly and escalate complex novel or high-risk issues appropriately. Experience identifying validating and exploiting weaknesses in 2 or more domains such as web applications APIs mobile applications cloud infrastructure enterprise applications databases networks servers IoT devices identity platforms directory services or AI-enabled systems. Ability to automate tasks with basic scripts or programs in at least one language such as Python PowerShell Bash Go C# JavaScript or similar. Basic Linux command-line experience and familiarity with Windows-based environments. Ability to read and understand code well enough to follow application behavior and identify security-relevant logic. Basic hands-on experience with at least one major cloud provider such as GCP AWS or Azure. Adversarial mindset with the ability to think from an attacker’s perspective while following rules of engagement and safety guidance. Clear written and verbal communication skills with the ability to explain technical findings concisely. Qualifications (Preferred Skills) One or more penetration testing or security certifications such as OSCP OSWE GPEN GXPN GWAPT PNPT eJPT or similar. Experience with CTFs Bug Bounty programs Vulnerability Disclosure Programs coordinated vulnerability research or public technical write-ups. Experience using AI tools to assist with reconnaissance code review vulnerability triage payload development reporting or remediation validation. Exposure to testing AI-enabled applications LLM-based systems AI agents RAG systems model integrations or AI-enabled workflows. Experience with mobile IoT embedded systems firmware reverse engineering or hardware security testing. Exposure to cloud and identity attack paths involving SSO MFA OAuth IAM secrets exposure conditional access or privilege escalation. Familiarity with tools such as Burp Suite Nmap Metasploit Frida Ghidra IDA BloodHound or cloud security testing tools. Curiosity humility and a desire to improve technical depth reporting quality and testing consistency. We offer P&G-sized projects and access to world leading IT partners and technologies from Day 1. Wide range of self-development possibilities (training and certifications paths). Competitive starting salary and benefits program (private health care P&G stock saving plans sport cards). Regular salary increases and possible promotions - in line with your results and performance. Opportunity to change role every few years to be in the best place for you and best for P&G. At Procter & Gamble we embrace a hybrid work model that combines the flexibility of remote work with the collaborative benefits of in-office engagement. Employees can enjoy the option to work from home two days a week while also spending time in the office to foster teamwork and enhance communication. At P&G #weseeequal We are an equal opportunity employer and value diversity at our company. At P&G we strive to build a culture where everyone feels welcome included and able to bring their full selves to work. We ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process. Please click here if you require an accommodation during the application process. Please make sure to wait to hear back from us regarding your accommodation before proceeding with the online assessment we thank you in advance for your patience. Kindly be advised that at P&G employment is exclusively extended on the basis of ""Umowa o Pracę"" (Full-time Employment Contract). Apply only if you agree to these conditions. Job Schedule Full time Job Number R000157572 Job Segmentation Experienced Professionals"

unlock: sign-up for free / login and use the searches from your home page
🔥 job listings updated in real time


For the 10 positions listed above we've analyzed the salary ranges, where available, and the resulting overall salary range is: 70K - 110K USD.

For 23 similar eJPT position(s) we've listed in the previous 30 days we've processed the salary ranges data as posted by employers in job descriptions and the resulting overall range is: 70K - 150K USD.

View highest-paying job

Note: If any discrepancies or 'wild' numbers appear this could be because of: typos in job postings, data source errors, ghost jobs, etc. We do not modify salary data inserted in JDs by employers nor use estimates.


Login & search by other job titles, a specific location or any keyword.
Additional custom search filters are available once you login.