Senior Security Penetration Tester

Boston, MA /
Technology – Security & Compliance /
Full-time
The Sr. Security Penetration Tester is responsible for internal penetration testing activities, supporting the application development team to resolve security vulnerabilities, resolving OWASP Top 10 vulnerabilities and working with cross functional teams to implement secure SDLC best practices.

Principal Responsibilities:

    • Perform penetration testing activities on Web Applications, Cloud Environments and Mobile Applications using black-box testing tools, in-depth penetration test (using shell scripts and manual testing) techniques, DAST & SAST tools.
    • Understand the application architectural components, business purpose of the application and code at high level. The resource will be responsible for assisting in architecting secure coding practices.
    • Researching and learning about information security trends, new penetration testing techniques, and best practices, and share findings with the team
    • Experience with manual and automated techniques for penetration testing (network equipment, servers, web applications, APIs, wireless, mobile, databases, and other information systems), as well as executing vulnerability assessments (injection, privilege escalation, fuzzing, buffer overflows, etc.)
    • Demonstrates a consistent track records of testing web applications for common web application security vulnerabilities as defined by OWASP, including input validation vulnerabilities, broken access controls, session management vulnerabilities, cross-site scripting issues, SQL injection and web server configuration issues
    • Programming – Python, Perl, Java, Shell Scripting (beneficial)
    • Tools – Proxies, Port Scanners, Vulnerability Scanners, Exploit Frameworks (ex: Burp, Nessus, Nmap, Metasploit)
    • Providing feedback and guidance to the development teams on best practices to resolve security vulnerabilities and provide input on mitigation strategies.

Experience/Education:

    • 7+ years of experience in Application Penetration Testing & Security Engineering responsibilities
    • 4-years College DegreeOSCP, GPEN or GXPN certified or ability to secure certification within six months of hire.
    • Proficiency with Application Security best practices. A background in managing GraphQL and React framework vulnerabilities is preferred.
    • Experience working with any markup languages and shell scripts 

Knowledge and Skills Required:

    • Perform Penetration Testing and Red Team techniques to discover and exploit vulnerabilities.
    • Perform automated and manual hands-on penetration security testing, identifying security risks within applications, security controls, and infrastructure.
    • Proven knowledge of OWASP Top 10 & SANS Top 20Ability to demonstrate deconstructing the Cyber Kill ChainProven capabilities investigating IDS/IPS to identify malicious traffic
    • Experienced with using syslog events and other security tools to build an end-to-end analysis of events and threats.
    • Log correlation to determine security events and managing alertsProven knowledge of application security methodologies, policies, standards and best practices
    • Ability to explain and articulate technical concepts using both technical and non-technical languageStrong oral and written communication skills
    • Plan, execute, and report on all testing activities and outcomes.
About Posh
We’re on a mission to power a billion helpful banking moments, and we’re using cutting-edge conversational AI to do it. Our platform powers digital assistants like Citadel’s Adel, TruWest’s Trudy, Salem Five’s Sally, and dozens more. We arm any financial institution with the capability to provide an exceptional, conversational customer experience regardless of their assets under management or the communities they serve.

This is an incredibly exciting time to consider joining Posh. In November 2021, we closed a $27.5mm Series A venture round that will allow us to continue investing in our product and people. In 2021, we doubled our team size from 20 to 40, and we increased our customer base by four times.  We have big goals, and we’re are looking for people to help us achieve them.
 
Why we're a great place to join
- We value growth. We want you to be smarter and more capable than the day you joined. To that end, we celebrate regular “growth days” for you to learn what you want.
- We’re building this together. We’ve designed our teams to be cross-functional, and we know a diversity of perspectives is required for success.
- We value you. We offer competitive compensation (cash and equity), benefits, and employee perks.
- Our technology is cutting-edge. We ship fast and always look for opportunities to improve our product.
- Our customers love our products. It’s the reason we’re growing, and the inspiration for new product ideas.
- We make mistakes. Building a company is hard, and we don’t get everything right every time.