Talent.com
Penetration Tester - Remote

Penetration Tester - Remote

501 CSAA Insurance Services, Inc.New York, United States
6 days ago
Job type
  • Full-time
  • Remote
Job description

Job Information

CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the top personal lines property and casualty insurance groups in the U.S. Our employees proudly live our core beliefs and fulfill our enduring purpose to help members prevent, prepare for and recover from life's uncertainties, and we're proud of the culture we create together. As we commit to progress over perfection, we recognize that every day is an opportunity to be innovative and adaptable. At CSAA IG, we hire good people for a brighter tomorrow. We are actively hiring for a Penetration Tester! Join us and support CSAA IG in achieving our goals.

Your Role : Are you a highly skilled Security professional that has a passion for identifying, assessing, and managing threats, vulnerabilities, and associated risks to enterprise information assets and applications? Bring your proficiency to help us craft and mature our Vulnerability and Offensive Security program. Work closely with our information technology teams to identify and reduce security risks in our IT infrastructure and business applications. You bring to this position a high-level of security expertise and a deep understanding of desktop, server, application and data storage vulnerabilities and how to discover and exploit them in a controlled environment. You'll take the lead and act as a subject matter expert for penetration testing and attack simulation in our data centers, cloud environments and critical business applications, helping us improve our overall threat posture. Help us re-think what it means to be a secure insurance provider in a fast-changing, highly competitive market.

Your work :

Conduct infrastructure, web application, API, and mobile application penetration testing.

Develop, document and administer the entire penetration testing lifecycle during engagements.

Conduct breach and attack simulation operations against CSAA systems to identify gaps in prevention, detection, or response.

Research, develop, and apply TTPs of relevant threat actors to simulated attack scenarios.

Provide subject matter expertise on the remediation of discovered vulnerabilities and gaps in security response.

Leverage threat intelligence to hunt for indicators of compromise and vulnerabilities.

Develop, deploy, manage and improve breach and attack simulation tools and related processes.

Design, develop and manage red and blue team exercises and processes contributing to purple team evaluation and response.

Provide team guidance and mentoring as a subject matter expert in purple team activities.

Required Experience, Education and Skills

Bachelor’s degree (in Information Technology or a related discipline) or equivalent experience

6 or more years of Information Technology and Security experience

5 or more years of hands-on penetration testing related experience related to infrastructure and web applications.

2 or more years hands-on experience with breach and attack simulation tools

Proficient knowledge of web development, including but not limited to Ruby, advanced JavaScript libraries (React, Angular, Knockout), Node.JS, JQuery, Object-Oriented Design, Web Services (REST / SOAP)

Professional experience with any of the following : Java, .NET, AWS, Functional programming, SQL, MongoDB, CouchDB, Neo4J, Hadoop, Cassandra, DynamoDB, ElasticSearch, Solr

Expert knowledge of OWASP Top 10 and ability to articulate web security risks.

Experience with MITRE ATT&CK framework and adversary tactics, techniques and procedures

Solid understanding of penetration testing standards and process, including the development of documentation such as rules of engagement, scope, and remediation reports

Familiarity with Information Security risk ranking scales and derivation.

Broad knowledge of IT Security technologies and a solid understanding of architecture, design, deployment and management of information systems

Experience testing solutions deployed in a public cloud environment (IaaS, PaaS, SaaS)

Recent experience with Agile development / Scrum teams and operating in a Kanban model.

Direct experience with common change management procedures and platforms

Solid understanding of TCP / IP, DNS, HTTP, HTTPS, VPN, SQL and other database technologies

CISSP, CEH, OSCP, GWAPT, GPEN, or other penetration testing and security-related certifications are highly desired.

What would make us excited about you?

Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)

Lives into cultural norms (e.g., willing to have cameras when it matters : helping onboard new team members, building relationships, etc.)

Travels as needed for role, including divisional / team meetings and other in-person meetings

Fulfills business needs, which may include investing extra time, helping other teams, etc

CSAA IG Careers

At CSAA IG, we’re proudly devoted to protecting our customers, our employees, our communities, and the world at large. We are on a climate journey to continue to do better for our people, our business, and our planet. Taking bold action and leading by example. We are citizens for a changing world, and we continually change to meet it.

Join us if you…

BELIEVE in a mission focused on building a community of service, rooted in inclusion and belonging.

COMMIT to being there for our customers and employees.

CREATE a sense of purpose that serves the greater good through innovation.

Recognition : We offer a total compensation package, performance bonus, 401(k) with a company match, and so much more!

Create a job alert for this search

Penetration Tester • New York, United States

Related jobs
Penetration Tester (Team Lead)

Penetration Tester (Team Lead)

Charterhouse Pte LtdSingapore, Michigan, Singapore
Full-time
Tester (Team Lead) - Min 8 years.Available junior penetration tester roles for candidates with lesser experience.We are looking for a Lead to guide and oversee advanced penetration testing and red ...Show moreLast updated: 30+ days ago
Penetration Tester, Offensive Security Operations (Network / Cloud / Application) - USDS

Penetration Tester, Offensive Security Operations (Network / Cloud / Application) - USDS

TikTokNew York
Full-time
About the TeamThe USDS Offensive Security and Privacy serves as the Independent Testing and Validation pillar for USDS.The team performs cyber threat simulations within the TikTok USDS environment ...Show moreLast updated: 30+ days ago
Penetration Test Engineer

Penetration Test Engineer

Radar Labs, IncJersey City, NJ, United States
Full-time
About the roleWe're looking for red team penetration test engineers.Radar is a high-throughput, data intensive application handling 1 billion+ API calls per day. Over the past year, Radar has been u...Show moreLast updated: 30+ days ago
Associate Penetration Tester

Associate Penetration Tester

FortraUnited States
Full-time
Ready to join us? Let's get started.The Associate Penetration Tester is responsible for performing security-related services for Digital Defense clients. Within Offensive Security Operations, the As...Show moreLast updated: 30+ days ago
  • Promoted
Automation Tester - Remote / Telecommute

Automation Tester - Remote / Telecommute

Cynet SystemsNew York, NY, US
Remote
Full-time
Must have automation knowledge in any framework (Ruby / Cucumber ADD on).Must have the ability to write or enhance the scenarios in Cucumber framework. Must have the ability to understand the existing...Show moreLast updated: 30+ days ago
Remote - QA Tester

Remote - QA Tester

Solgenie TechnologiesRemote, Work from Home, United States of America
Remote
Part-time
Role : QA TesterLocation : Remote (Anywhere)Duration : 1 year Details : Need an independent tester with experience in writing and executing test cases. Strong understanding of Cypress, Playwright,...Show moreLast updated: 30+ days ago
Cyara Tester ___Remote ___ Contract

Cyara Tester ___Remote ___ Contract

AcestackJersey City, NJ, United States
Remote
Temporary
Quick Apply
Job Title : Cyara Tester Location : Remote, but once in a quarter office visit Long Term Contract &...Show moreLast updated: 1 day ago
Remote Beta Tester - $45 per hour

Remote Beta Tester - $45 per hour

Great LionBayonne, New Jersey
Remote
Part-time +1
Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. We guarantee 15-25 hours per week with an hourly pay of bet...Show moreLast updated: 30+ days ago
Penetration Tester

Penetration Tester

AiritosUS
Temporary
Quick Apply
Penetration Tester Location : Remote in PST, MST or CST Type : 6 Month Contract to Hire Position Overview : The primary responsibility of the Sr. DevSecOps Engineer – Cyber Security i...Show moreLast updated: 30+ days ago
Penetration Tester

Penetration Tester

Arrow Search PartnersNew York, New York
Full-time
Our client is a rapidly growing financial consulting firm that works with a robust clientele and strategically positioned to assist through a range of routine and complex business scenarios.They ar...Show moreLast updated: 30+ days ago
Senior Penetration Tester - Assessments & Exercises Vice President

Senior Penetration Tester - Assessments & Exercises Vice President

JPMorgan Chase & Co.Brooklyn, NY, United States
Full-time
This role is also open to Atlanta GA | Brooklyn, NY | Chicago IL | Columbus OH | Houston TX | Jersey City NJ | McLean VA | Tampa FL | Washington DC | Wilmington DE. Contribute to leading-edge securi...Show moreLast updated: 30+ days ago
Remote - UAT Tester

Remote - UAT Tester

JPS Tech Solutions LLCRemote, Work from Home, United States of America
Remote
Part-time
Hello All, I am John from JPS Tech Solutions LLC.We are currently seeking qualified candidates for UAT Tester Role with our client in the US and would appreciate receiving suitable applications...Show moreLast updated: 30+ days ago
Remote - Performance Tester

Remote - Performance Tester

Intone NetworksRemote, Work from Home, United States of America
Remote
Part-time
Job Title : Performance Tester Type : FTC (5 Day's Onsite) Location : Columbus OH Experience : 10+ Years Only Tier-1 Company profiles Performance Tester : LoadRunner, JMeter, Blazemeter alo...Show moreLast updated: 30+ days ago
Senior Specialist, Application Penetration Tester

Senior Specialist, Application Penetration Tester

KPMG-UnitedStatesNew York, NY
Full-time
Senior Specialist, Application Penetration Tester.The KPMG Advisory practice is currently our fastest growing practice.We are seeing tremendous client demand, and looking forward we don't anticipat...Show moreLast updated: 30+ days ago
  • Promoted
Senior Specialist, MAST Application Penetration Tester

Senior Specialist, MAST Application Penetration Tester

KPMGNew York, NY, United States
Full-time
KPMG Advisory practice is currently our fastest growing practice.We are seeing tremendous client demand, and looking forward we do not anticipate that slowing down. In this ever-changing market envi...Show moreLast updated: 7 days ago
Application Security Penetration Tester

Application Security Penetration Tester

Synergistic Systems IncJersey City, NJ, US
Full-time
Application Security Penetration Tester.A large financial services organization is seeking an Application Security Penetration Tester for a. This role supports the organization’s Technology Risk ini...Show moreLast updated: 30+ days ago
Penetration Testing Associate

Penetration Testing Associate

Drawbridge PartnersJersey City, NJ, United States
Full-time
PENETRATION TESTING ASSOCIATEWorking at DrawbridgeAt Drawbridge, we are committed to attracting and retaining the best individuals who enjoy working in a dynamic environment.You will be joining an ...Show moreLast updated: 30+ days ago
  • Promoted
Penetration Tester

Penetration Tester

VirtualVocationsBronx, New York, United States
Full-time
A company is looking for a Penetration Tester to conduct security assessments and penetration tests on various systems.Key Responsibilities Conduct web application, API, network, and cloud penetr...Show moreLast updated: 1 day ago