Demo

Penetration Tester

Insight Global
Scottsdale, AZ Full Time
POSTED ON 2/12/2025
AVAILABLE BEFORE 5/4/2025

The Senior Software Engineer III is primarily responsible for penetration testing a variety of environments based on methodical adherence to attack-scoring frameworks. They will build, deploy, and maintain new security automation and orchestration tooling to integrate scanning and monitoring for compliance within existing pipelines. They also review and guide internal teams in developing more secure codebases, while educating them on best practices to build a strong security-first culture.

The following are essential accountabilities :

In-Depth Penetration Testing & Threat Modeling

Conduct ongoing internal and 3rd party vendor penetration testing and auditing aligned with compliance and legal objectives.

Perform threat modeling in accordance with OWASP Top 10, MITRE ATT&CK, and similar attack-scoring frameworks.

Monitor, test, and proactively report on current threats and vulnerabilities to respective teams.

Research and educate on emerging threats within similar environments and landscapes, along with offering remediation solutions for such.

Security Tooling, Automation, & Orchestration

Build, ship, and maintain various security packages to internal application codebases for automation.

Identify vulnerable dependencies across the organization and work with individual teams to resolve them.

Install programmatic measures to prevent and mitigate repeat vulnerability occurrences.

Integrate security monitoring within existing CI / CD pipelines. Work with Ansible and Jenkins is a plus.

Build complex regex and other pattern identification scripts and parsing to identify potential injection attempts.

Building and integrating APIs from disparate systems for orchestrated audits and scans.

Knowledge and experiences with data protection concepts such as : (a) data obfuscation, anonymization, & de-identification; (b) secrets management; and (c) vault services.

Experience building application parameterized / prepared-statement query interfaces a plus.

Secure-SDLC (sSDLC) Guidance, Codebase Review, & Support

Develop detailed security design and procedures across the enterprise to drive a standardized set of requirements and align with internal policies.

Lead secure-SDLC and product security maturity efforts to adopt a shift-left approach to security.

Conduct platform / service workload design and architecture reviews, as well as audit source code for compliance.

Monitoring, Logging, & Reporting

Parse a variety of debug logs for determining behavioral baselines to better formulate granular internal policies and standards.

Orchestrate log ingestion into tools and tuning rulesets for advanced metrics reporting on enterprise-wide security posture.

Build leaderboards and reporting interfaces on current and forecasted KPIs and risk indicators.

Other General Duties

Provide product security related coaching and mentoring to elevate security expertise of development teams.

Take ownership of security decisions made in the engineering organization by helping organization members make clear decisions in alignment with organizational goals, backing decisions made, and taking responsibility for their success.

Foster a company-wide positive culture across by having conversations based on organizational strategy and principles to create alignment.

Ensure security goals are understood and continuously worked towards across the organization.

Takes ownership and responsibility for organizational security practices and processes and their continuous improvement.

Effectively handle risk, change, and uncertainty across the organization.

Facilitate organization-wide discussions, ensuring that everyone has an opportunity to share their opinion and be heard, and that discussion outcomes are tied to stated goals.

Actively advance a culture of documentation and knowledge sharing across the organization.

Respond in a timely manner to on-call security notifications when scheduled on monthly rotation.

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees in this position.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity / affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and / or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal. com.

To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy : https : / / insightglobal.com / workforce-privacy-policy / .

Experience with AWS or other cloud platforms

Experience with MySQL

Any credentials from the following certification bodies : ISC2, ISACA, CompTIA, GIAC, AWS, Azure, TOGAF, SABSA

Participation in bug hunting / bug bounty communities is a plus.

Experience with PCI / GDPR / or CCPA a plus.

5-15 Years of Experience of Penetration Testing, with a focus on Web Application Testing

Experience with Kali Linux Tools (kali. org / tools / ) such as Burp, Zap or Metasploit, OR Burp Suite, or Kali Linux Alternatives.

Metasploit, burp suite, Zap, Nessus

Web application penetration testing apps open source

Experience with Vulnerability Scanning

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Penetration Tester?

Sign up to receive alerts about other jobs on the Penetration Tester career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$131,745 - $167,716
Income Estimation: 
$144,503 - $184,592
Income Estimation: 
$102,541 - $137,871
Income Estimation: 
$153,752 - $200,235
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,167 - $152,295
Income Estimation: 
$146,673 - $180,130
Income Estimation: 
$146,673 - $180,130
Income Estimation: 
$176,149 - $220,529
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Insight Global

Insight Global
Hired Organization Address Salt Lake, UT Full Time
Job Description Job Description Day to Day : Insight Global is looking for a Rad Tech that can accurately position patie...
Insight Global
Hired Organization Address Topeka, KS Full Time
Insight Global is seeking a Interventional Radiology Technologist for a job in Topeka, Kansas. Job Description & Require...
Insight Global
Hired Organization Address Portland, OR Full Time
Insight Global is seeking engineers to provide 24 / 7 technical support for real-time operations of the electric transmi...
Insight Global
Hired Organization Address Parker, CO Full Time
JOB DESCRIPTION : Insight Global is seeking to hire a receptionist at a brand-new office who will assist with their expe...

Not the job you're looking for? Here are some other Penetration Tester jobs in the Scottsdale, AZ area that may be a better fit.

Penetration Tester in Chandler AZ

Syntricate Technologies, Chandler, AZ

Sr. Penetration Tester

MUFG, Tempe, AZ

AI Assistant is available now!

Feel free to start your new journey!