Senior Cyber Penetration Tester & Engineer

Remote Full-time
PURPOSE: UNFI is looking for an experienced technical Cybersecurity Penetration Tester and Engineer Senior to help us create a resilient food supply chain. The Cyber Penetration Tester and Engineer Senior will focus on performing threat emulations and identifying cybersecurity issues within the UNFI environment against a wide range of technologies and systems, performing technical penetration testing of APIs, web applications, networks, cloud services, databases, directory services, and infrastructure. They will be part of the cybersecurity threat and emulation team and will collaborate with staff from other teams across UNFI. While management responsibilities are not part of the role, the expectation is that they can lead engagements, communicate technical details to senior leadership, mentor junior staff, provide technical direction to the program. Coding skills and a passion for cybersecurity is a must, with a preference for testers who view cybersecurity and penetration testing as more than just a job but also a hobby. ESSENTIAL FUNCTIONS: Job Responsibilities | Percentage • Perform technical penetration testing of APIs, web applications, networks, cloud services, databases, directory services, and infrastructure. - 75% • Strategic attack simulation by analyzing UNFI's internal and external attack surface and crafting bespoke penetration strategies. - 10% • Writing comprehensive reports outlining identified vulnerabilities, potential exploitation paths. Provide remediation guidance and recommendations from the assessments and support any security questions from network, system, and/or application owners. - 10% • Assess UNFI's software development and cloud infrastructure from a security perspective and help drive internal security standards. - 5% Total - 100% JOB REQUIREMENTS: Education/Certifications/or Equivalent combination of education training and experience: • At least 1 industry leading or senior level cybersecurity penetration certification, for example: Offensive Security Certified Professional (OSCP), GIAC Penetration Tester Certification (GPEN), GIAC Web Application Penetration Tester (GWATP), GIAC Cloud Penetration Tester (GCPN) or EC-Council Licensed Penetration Tester (LPT) Master. • Active GitHub repository account with examples of security tools, scripts, exploits developed OR evidence of past and current artifacts. Experience: • 8+ years of hands-on cybersecurity experience within IT environments. • 5+ years of experience performing penetration testing and vulnerability assessments. Knowledge/Skills/Abilities: • Advanced penetration testing skills across both tools and scripting abilities. Expertise with the following tools: various C2s, Burp Suite, Nmap, Wireshark, Bloodhound. Expertise with cybersecurity scripting in Python, PowerShell, or Go to manipulate vulnerabilities and demonstrate potential exploits. • Ability to employ OSINT techniques to maximize attack vectors, simulating real-world cyber threats. • Skills in developing implants and evading common security tools. • Ability to critically examine an organization and system using knowledge of tactics, techniques, and procedures associated with malicious insider activity, organized crime groups, and both state and non-state sponsored threat actors. • Knowledge of web application and cloud infrastructure best practices and understanding of how to exploit misconfigurations and vulnerabilities. • Knowledge of network access, identity and access management, including public key infrastructure and understanding of how to exploit misconfigurations and vulnerabilities. • Experience creating rules of engagement, test plans, scripts to aid testing efforts, and technical assessment reports that detail findings and remediation efforts. • Ability to translate technical findings into actionable insights. • Ability to mentor junior staff and transfer technical knowledge as well as contribute to the team's knowledge sharing. PHYSICAL ENVIRONMENT/DEMANDS: • Some travel may be required. • Most work is performed in a temperature-controlled office environment. • Incumbent may sit for long periods of time at a desk or computer terminal. • While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear. • Incumbent may use calculators, keyboards, telephones, and other office equipment in the course of a normal workday. • Stooping, bending, twisting, and reaching may be required in completion of job duties. The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location. Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Remote RN Case Manager & Telephone Advice Nurse - Unlock Your Potential with a $10,000 Sign-On Bonus

Remote Full-time

Data Modeling Lead

Remote Full-time

Experienced Flexible Career Opportunity with High Earning Potential - Leadership Development and Unlimited Growth

Remote Full-time

Flex Schedule Data Entry Specialist (Hiring Immediately)

Remote Full-time

Experienced Customer Service Representative – Remote Work Opportunity Ideal for College Students and Individuals Seeking Flexible Schedules with arenaflex

Remote Full-time

Field Sales Support Engineer Asc- Early Career

Remote Full-time

Microsoft Certified Trainer/Professional (Remote)

Remote Full-time

Experienced Customer Support Specialist – Live Chat and Technical Issue Resolution for Veterinary Professionals at blithequark

Remote Full-time

**Experienced Data Entry Specialist – Remote Logistics Operations**

Remote Full-time

Appointment Coordinator

Remote Full-time
← Back to Home