Offensive Security Engineer, Penetration Testing
Brak informacji o wynagrodzeniu
MidFull-time·Umowa o pracę
#411091·Dodano 2 dni temu·5
Źródło: P>ech Stack / Keywords
SecurityTestingGoCloudNetworksIoTAICybersecurity
Firma i stanowisko
The Information Security Protect organization at Procter & Gamble conducts simulated exercises to test security controls across the enterprise and improve applications, detection, and response capabilities.
Wymagania
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, or related field, or 2+ years relevant experience.
- 2+ years experience in penetration testing, application security testing, or related security roles.
- Ability to lead penetration tests, manage execution, document results, and escalate novel or high-risk issues.
- Experience identifying and exploiting weaknesses in at least two domains such as web applications, APIs, mobile apps, cloud infrastructure, or networks.
- Ability to automate tasks with basic scripts or programs in languages such as Python, PowerShell, Bash, Go, C#, JavaScript, or similar.
- Basic Linux command-line experience and familiarity with Windows environments.
- Ability to read and understand code to follow application behavior and security logic.
- Basic hands-on experience with major cloud providers like GCP, AWS, or Azure.
- Adversarial mindset with attacker perspective while adhering to rules of engagement.
- Clear written and verbal communication skills for explaining technical findings.
Nice to have:
- Penetration testing or security certifications such as OSCP, OSWE, GPEN, GXPN, GWAPT, PNPT, eJPT.
- Experience with CTFs, Bug Bounty programs, Vulnerability Disclosure Programs, or public technical write-ups.
- Experience using AI tools for reconnaissance, code review, vulnerability triage, payload development, reporting, or remediation validation.
- Exposure to testing AI-enabled applications, LLM-based systems, AI agents, RAG systems.
- Experience with mobile, IoT, embedded systems, firmware, reverse engineering, or hardware security testing.
- Knowledge of cloud and identity attack paths involving SSO, MFA, OAuth, IAM, secrets exposure, conditional access, privilege escalation.
- Familiarity with tools such as Burp Suite, Nmap, Metasploit, Frida, Ghidra, IDA, BloodHound, or cloud security testing tools.
Obowiązki
- Lead defined-scope penetration tests across websites, services, APIs, infrastructure, cloud environments, networks, IoT devices, mobile applications, and enterprise applications.
- Partner with Intake Management and stakeholders to confirm objectives, access, rules of engagement, and readiness.
- Execute reconnaissance, vulnerability discovery, exploitation, evidence collection, reporting, and remediation validation.
- Identify, validate, exploit, and document security vulnerabilities within approved scope.
- Validate related vulnerabilities to demonstrate realistic impact and escalate complex attack chains.
- Test for control gaps and document weaknesses in preventative or detective controls.
- Investigate and validate Vulnerability Disclosure Program and Bug Bounty findings, escalating as needed.
- Collaborate with engineering, product, cloud, infrastructure, and security teams to explain findings.
- Use approved scripts, templates, automation, and AI-assisted workflows to improve testing efficiency.
- Assist in testing AI-enabled applications and integrations for specific risks.
- Produce clear standardized reports with reproduction steps, evidence, impact, and remediation guidance.
- Contribute to team knowledge sharing, documentation, test notes, templates, and process improvements.
Benefity
- P&G-sized projects and access to leading IT partners and technologies from Day 1.
- Wide range of self-development possibilities including training and certification paths.
- Competitive starting salary and benefits including private health care, P&G stock, saving plans, and sport cards.
- Regular salary increases and possible promotions based on results and performance.
- Opportunity to change role every few years to best fit employee and company needs.
- Hybrid work model allowing two days of remote work per week coupled with in-office collaboration.
Opieka zdrowotna
Karta sportowa
Udziały pracownicze
Inne informacje
Employment is exclusively extended on the basis of "Umowa o Pracę" (Full-time Employment Contract). Apply only if you agree to these conditions. P&G provides reasonable accommodation for individuals with disabilities during the application or interview process. We are an equal opportunity employer valuing diversity and inclusion.
P&G
29 aktywnych ofert