Company

Capital GroupSee more

addressAddressNew York, NY
type Form of workFull-Time
CategoryInformation Technology

Job description

"I can succeed as a Senior Application Security and Penetration Testing Engineer at Capital Group."
As the Senior Application Security ("AppSec") and Penetration Testing Engineer you are an individual contributor in the Capital Group (CG) AppSec team. The CG AppSec team is part of Information Security in CG's Information Technology Group. In the role you will be performing web application and network penetration tests, code reviews, security design reviews, red/purple team assessments, and providing security signoffs for technology initiatives. You will be discovering security issues by threat modeling, code reviews (Java, TypeScript/JavaScript, Python), and dynamic application testing. As the Senior Application Security ("AppSec") and Penetration Testing Engineer you will also be responsible for performing red and purple team assessments for Capital Group's detective security controls. The team members are geographically dispersed with varying experience levels. As the senior member on the team, you will be creating proof-of-concept exploits for the security issues discovered. You will be responsible for coordinating and communicating with the key technology stakeholders for delivery of security assessments and explaining technology risks and mitigations. This role is hybrid (in-office 3 days/week) and can be in Los Angeles CA, Irvine CA, San Antonio TX, or New York NY depending on candidate current location and/or preference.
In addition, you will be responsible for:
  • You will be performing AppSec reviews including threat modeling, code reviews, and Penetration Testing.
  • You will leverage your experience with SAST, DAST, SCA tool findings and translating them to severity of risks to perform this in Capital Group's technology environment.
  • You will write clear, succinct, and effective technical documentation summarizing your findings, risks, and recommendations.
  • You will write automated proof-of-concepts, and automated security tests by authoring security testing tools.
  • You will collaborate with technology stakeholders and advise on risks for technology solutions.
  • You will perform red and purple team tests of detective tooling including EDR tools, security telemetry tools, anti-virus software, having knowledge of MITRE ATT&CK Framework (Cloud, macOS, Windows, Linux), AI-based software systems.
  • You will communicate effectively and have an empathetic outlook towards development teams by authoring clear, actionable guidance on writing secure code.
  • You will effectively present to development teams educating them on secure development.
  • You will create and organize Capture-the-Flag competitions and participate in such competitions.

"I am the person Capital Group is looking for."
  • You have a bachelor's degree in computer science, a related field, or equivalent experience.
  • You have a minimum of 5 years of experience in Application Security, Penetration Testing.
  • You have a strong understanding of network security, TCP/IP, DNS, TLS, HTTP, IPSec, 802.11, etc.
  • You have experience with security protocols and/or technologies such as REST APIs, Burp Suite, ZAP, Linux, Windows, macOS, nmap, Metasploit, Powersploit, Lolbins, etc.
  • You have the ability to automate tasks in Python, bash, Java, C/C#/C++, Rust, etc.
  • You have a strong understanding of attacks in AWS, Azure, GCP, OAuth, websockets, etc.
  • You have excellent communication skills (written, oral), with the ability to simplify and document complex technical details to both technical and non-technical audiences.
  • You can learn quickly and have a track record of developing a deep understanding of systems and risks to the business.
  • You can work independently and take the initiative to drive security initiatives forward.
  • You can juggle multiple tasks and coordinate/delegate to achieve speedy resolutions to Application Security-related security incidents working with Security operations.

Southern California Base Salary Range: $148,045-$236,872
San Antonio Base Salary Range: $121,706-$194,730
New York Base Salary Range: $156,935-$251,096
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits here.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
Refer code: 8717853. Capital Group - The previous day - 2024-03-24 21:15

Capital Group

New York, NY
Popular Testing Engineer jobs in top cities
Jobs feed

Construction Project Manager

Refresh Renovations Portland

Lake Oswego, OR

Summer Internship (Ph.D. Student, 90 Days, Onsite or Remote)

Docomo Innovations, Inc.

Sunnyvale, CA

Pest Control Service Rep

Hawx Services, Llc

Ace, TX

$18.00 - $20.00 per hour

Administrative Assistant

The Nectar Group

Lone Tree, CO

Quality Assurance Investigator

Divine House

Willmar, MN

Competitive Wages + Benefits

Hospice Registered Nurse

Gentiva Hospice

Houston, TX

Administrative Assistant II - Fire Department

City Of Keller

Keller, TX

Registered Nurse Med-Surg Tele PRN

Hca Florida Kendall Hospital

Miami, FL

ICU RN PRN

Tristar Greenview Regional Hospital

Bowling Green, KY

Share jobs with friends

Related jobs

Senior Application Security And Penetration Testing Engineer

Security Engineer I, Offensive Security Penetration Testing

Amazon.com

New York, NY

a week ago - seen

Test and Integration Engineer (On-site)

Bae Systems

New York, NY

2 weeks ago - seen

Engineer - Fire Protection

Guardian Fire Testing Laboratories, Inc.

$80,000 - $95,000 a year

Buffalo, NY

4 weeks ago - seen

Senior Staff Engineer - Energy Storage & Batteries

Intertek Testing Services Na Inc

Cortland, NY

4 weeks ago - seen

Senior Project Engineer - HAZLOC Regulatory Compliance

Intertek Testing Services Na Inc

Cortland, NY

4 weeks ago - seen

TEST ENGINEER, MSP - SEIT

York State Department Of Labor

New York, NY

4 weeks ago - seen

Ariba QA / Testing Engineer

Apn Consulting

New York, NY

2 months ago - seen

Test Engineer

Dons Company

New York, NY

2 months ago - seen

Flight Test Engineer

Choice

Melville, NY

2 months ago - seen

Aerospace Test Engineer

Choice

Melville, NY

2 months ago - seen

Senior Automation & Test Engineer

Inficon

$100,000 - $140,000 a year

Syracuse, NY

2 months ago - seen

Quality Control & Testing Engineer

Afficiency

New York, NY

2 months ago - seen

Field Test Engineer

K & M Systems Inc

New York, NY

2 months ago - seen

Intern, Test Engineer

Leviton

New York, NY

2 months ago - seen

Systems Engineering, Integration & Testing (SEIT) Sensor Engineer

Vertex Aerospace

Jamaica, NY

2 months ago - seen

Mobile Testing Engineer

Intersources Inc.

New York, NY

2 months ago - seen