Day-to-Day
Insight Global is seeking a Senior Penetration Tester to join our client's Cybersecurity Architecture & Security Engineering team.
This is a strategic role focused on validating the security of our client's Security products and ensuring they meet the exceptionally high security standards expected of our client's brand.
You will be assigned to our client's Security products throughout the development lifecycle, working closely with engineering teams to understand the product architecture, functionality, and potential areas of risk before formal testing begins.
You will plan and execute penetration testing activities across cloud services, APIs, web applications, Windows applications, endpoint technologies, and associated infrastructure, identifying vulnerabilities and validating attack paths through both manual testing and automated tooling.
Following assessments, you will produce detailed reports, demonstrate findings using clear evidence, and work directly with engineering teams to remediate issues and validate fixes.
You will also proactively investigate potential security concerns, contribute to release readiness activities, and help ensure security assessments do not become a bottleneck to product delivery.
Must-Haves
- 8+ years of penetration testing experience.
- Strong experience testing cloud environments, web applications, APIs, and Windows applications.
- Expertise in manual penetration testing and vulnerability assessment techniques.
- Experience using tools such as Burp Suite, Veracode, and similar security testing platforms.
- Strong understanding of application security, OWASP Top 10, and secure development practices.
- Experience identifying, documenting, and communicating security vulnerabilities and remediation plans.
- Ability to review source code and validate security fixes.
- Knowledge of adversary tactics, techniques, and procedures (TTPs).
- Strong scripting/programming knowledge in languages such as Python, JavaScript, or C#.
- Excellent communication skills with the ability to influence engineering, product, and leadership teams.
- Experience working directly with engineering teams to improve security throughout the SDLC.
Plusses
- Experience testing endpoint security or EDR products.
- Azure, AWS, or GCP security testing experience.
- Experience with Windows endpoint technologies and operating systems.
- Knowledge of MITRE ATT&CK, threat modelling, and secure design reviews.
- Experience with CI/CD and DevSecOps security practices.
- CREST, OSCP, OSEP, CRTO, CHECK, or equivalent certifications.
- Experience leveraging AI-assisted security testing tools.
- Previous experience within a product-led or enterprise software organisation.