採用
必須スキル
Python
JavaScript
AWS
GCP
Azure
JOB DESCRIPTIONJob Title: Senior Analyst
- Penetration Tester
Location: Hybrid (2 days in the office)
Type: Full Time
Role overview
We are looking for a Senior Penetration Tester to lead testing across web applications, APIs, cloud services (Azure, AWS, GCP) and internal environments. You’ll work closely with App Sec, cloud, vulnerability, and threat hunting teams, using Veracode and Burp as core tools and following up with deep manual testing. The role includes occasional planned evening and weekend work for production testing, with comp days so your week still averages ~40 hours / 5 days.
Key responsibilities
- Lead penetration tests for web and API applications, including modern JavaScript apps, Word Press and Apache-based services.
- Use Veracode SAST/DAST and Burp Suite to identify issues, then perform manual testing to uncover logic, authorization, and high-impact vulnerabilities.
- Test Azure, AWS and GCP environments using tools like Scout Suite, Prowler, Pacu (or similar) to find misconfigurations and escalation paths.
- Assess Active Directory and Azure AD using Blood Hound (and similar tools) to identify and validate attack paths.
- Perform security testing of AI/ML/LLM-backed features and integrations to identify data leakage, unsafe integrations and abuse paths.
- Manually retest vulnerabilities—primarily on the external attack surface, with some internal scope—to confirm that remediation is effective.
- Work with threat hunters and detection engineers to simulate attacks and validate that new or updated detections behave as intended and don’t create excessive noise.
- Produce clear reports and explain technical findings, impact and remediation options to both technical and non-technical stakeholders.
- Participate in planned evening and weekend testing windows, with weekdays off in exchange so total time stays within normal full-time hours.
Required experience & skills
- 5+ years of hands-on penetration testing or offensive security experience, including leading complex engagements.
- Strong experience in web and API testing, including OWASP-style issues and business logic/authorization flaws.
- Practical experience with Veracode (or a similar SAST/DAST platform) and advanced use of Burp Suite.
- Experience testing all three major clouds: Azure, AWS, and GCP.
- Hands-on assessment of AD/Azure AD using Blood Hound or comparable tooling.
- Experience testing AI/ML/LLM-backed systems or AI-enabled features from a security perspective.
- Comfortable with planned off-hours work (evenings/weekends) when required, with comp days to keep workload reasonable.
- Strong written and verbal communication skills in English.
Preferred qualifications
- Mobile app testing experience (e.g., MobSF, Frida).
- Familiarity with additional AD tools (e.g., Ping Castle).
- Experience building custom scripts, Po Cs, or exploits (Python, PowerShell, Bash, etc.) to exercise vulnerabilities and test controls.
- Certifications such as OSCP, GPEN, GXPN, CEH or similar.
Working in our international team
- Lead and participate in engagements with stakeholders across multiple regions.
- Heavy use of written communication (tickets, docs, reports).
- Contribute to an environment that encourages sharing research, tooling, and lessons.
- Close collaboration with Vulnerability and Threat Hunting teams.
総閲覧数
0
応募クリック数
0
模擬応募者数
0
スクラップ
0
類似の求人

Principal Security Engineer
Lennar ·

Staff Security Engineer, Application Security
Robinhood · Menlo Park, CA

Staff Product Cybersecurity Engineer - Vehicle Security
General Motors · 2 Locations

Senior Software Engineer, Security Development
Asana · San Francisco

Senior Security Compliance Analyst - Public Sector - Information Security
Elastic · United States
Syscoについて

Sysco
PublicSysco Corporation is the largest food distribution company in North America, supplying restaurants, healthcare facilities, hotels, and other foodservice operations. The company distributes food products, kitchen equipment, and related supplies to approximately 700,000 customer locations.
10,001+
従業員数
Houston
本社所在地
$38B
企業価値
レビュー
2.7
3件のレビュー
ワークライフバランス
2.0
報酬
3.0
企業文化
2.5
キャリア
3.5
経営陣
2.5
25%
友人に勧める
良い点
Achievement recognition programs
Upper-level management experience opportunities
Performance-based rewards
改善点
Poor product quality
High stress levels
Stingy equipment and upgrade decisions
給与レンジ
2件のデータ
Junior/L3
Junior/L3 · Data Analyst
0件のレポート
$103,000
年収総額
基本給
-
ストック
-
ボーナス
-
$87,550
$118,450
面接体験
4件の面接
難易度
1.8
/ 5
内定率
25%
体験
ポジティブ 25%
普通 75%
ネガティブ 0%
面接プロセス
1
Application Review
2
HR Screen
3
Hiring Manager Interview
4
Background Check
5
Offer
よくある質問
Past Experience
Behavioral/STAR
Culture Fit
Physical Requirements
Availability/Schedule
ニュース&話題
Sysco shares slip after report of $29B Restaurant Depot acquisition - MSN
MSN
News
·
3d ago
Lbp Am Sa Has $2.61 Million Stock Position in Sysco Corporation $SYY - MarketBeat
MarketBeat
News
·
3d ago
Dividend Aristocrat Sysco (SYY) Boosts Quarterly Dividend by 1.9% - TipRanks
TipRanks
News
·
4d ago
Sysco Corporation Increases Quarterly Cash Dividend to $0.55 per Share - Quiver Quantitative
Quiver Quantitative
News
·
4d ago