Requirement for Sr Penetration Tester Job at Kairos Technologies, Plano, TX

RXV4cVkyTVVDM1V0VmJxbHpHMWMvZVpwelE9PQ==
  • Kairos Technologies
  • Plano, TX

Job Description

Hi ,

Please let me know if you're comfortable with the position detailed below. This position is an urgent hire.

Job Title: Sr Penetration Tester

Location: Plano, TX---Hybrid 3 days

Duration : 6-12 months Contract to hire

Only Locals

• Experience conducting manual API and mobile PenTest using burp suite. Proficient in understanding application-level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, weak cryptography, authentication flaws etc.

Skilled in performing penetration tests on web APIs and mobile apps before release. MITRE ATT&CK working on Red Teaming TTPs and Threat Modelling.

Leveraging Bash, PowerShell and Python automation.

• API testing: Postman, SoapUI, Crackmapexec, Hash cat, Responder, Bloodhound, Impacket, Postman

Performing manual testing and identifying vulnerabilities such as Cross-Site Request Forgery (CSRF), Cross-Site Scripting (XSS), SQL Injection, privilege escalations, authentication weaknesses, access control weaknesses, use of insecure cryptographic protocols, security misconfigurations.

Summary

Within the Cyber Fusion Center, the Offensive Security Team continuously evaluates PepsiCo's cyber security posture through penetration tests and red team engagements to proactively identify gaps and drive mitigations to minimize PepsiCo's cyber risk exposure.

Responsibilities

• Conduct penetration tests across Web applications, APIs, Mobile applications, infrastructure, cloud environments, and devices.

• Conduct red team engagements across complex environments (including operational technologies).

• Drive all phases of penetration tests and red team engagements, including Scoping, planning, communications, timelines, and execution of key activities (reconnaissance, vulnerability identification, exploitation, and reporting)

• Develop in-depth reports (issue, severity, impact, remediation recommendations) for penetration tests and red team engagements.

• Develop tools and techniques to automate, scale, and accelerate adversary emulation capabilities and vulnerability discovery.

• Develop exploits and POCs to evade defensive countermeasures and emulate threat actor TTPs.

• Establish and mature team documentation, processes, procedures, and team KPIs.

• Mentor penetration testers, red team members, and other functions where needed to drive unified and holistic outcomes.

• Manage third-party pen test and red team engagements to ensure high-quality products and deliverables

• Support offensive security research, innovation, and testing across emerging capabilities (e.g. AI, LLM, ML, NLP, Smart Contracts, etc.).

Accountabilities

1. Execute on projects, objectives, and deliverables in alignments with team vision, mission, and goals.

2. Routinely develop and update offensive security documentation, processes, and technologies to adapt to emerging threat landscape.

3. Develop automation to scale global offensive capabilities and operational resiliency.

4. Collaborate with partner teams, service owners, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings.

5. Create and deliver trainings; and participate in security reviews, audits, on-site engagements, and support incidents after-hours when required

Years of experience

5+ years of experience in a technical security role (e.g. Penetration Testing, Red Team, Application Security, Infrastructure Security); or master's degree in computer science/engineering or related cyber field, and 2 years of relevant experience.

Mandatory Technical Skills

1. Advanced knowledge of security tools (Burp Suite, Metasploit, Cobalt Strike, Empire, Nmap, bloodhound, etc.) and multiple operating systems (e.g. Windows, Linux).

2. Proficient in at least one scripting language (Python, bash, PowerShell) or one programming language (Java, C#, C++).

3. Experience in multiple security domains (e.g. Network security, Application Security, Infrastructure Security, Cloud Security, Security operations).

4. Experience in aligning threat and vulnerability management efforts to frameworks and control objectives - MITRE ATT&CK, NIST CSF, ISO27001, CIS, OWASP.

5. Familiarity with defensive and monitoring technologies such as Intrusion prevention/detection systems (IPS/IDS), Web application firewalls (WAF), security information and event management systems (SIEMs), and endpoint detection/response (EDR) tools, as well as user and entity behavior analytics (UEBA).

6. Experience in developing offensive security tooling and automation is a plus.

Laxman Andoli | Lead – TAG | Kairos Technologies Inc

M : 972.848.7314 | O: 214.389.5616 Ext 302 | E:  [email protected]

 

Job Tags

Contract work, Local area, Immediate start,

Similar Jobs

Catalis Dental Lab Partners

Dental Lab Removable Technician Job at Catalis Dental Lab Partners

 ...About Us: Pan-Am Dental, part of the Catalis Dental Lab Partners premier network, is a full-service dental lab specializing in Crown & Bridge, Flexible...  ...denture materials . Assist with training junior technicians when necessary. Qualifications: Experience:... 

Clean Earth

Water Treatment Operator Job at Clean Earth

 ...waste solutions to retailers, pharmacies, hospitals, government operations, harbors, manufacturers, and consumers. Clean Earth ensures...  ...Loved Workplaces 2022 by Newsweek! Job Description Water Treatment Operator (Environmental Technician II) will be responsible... 

Optum

Licensed Practical Nurse - Allergy - Part Time Job at Optum

Join Our Team as a Licensed Practical Nurse (LPN)!$1,250 Sign-On Bonus for External Candidates!Part-Time Position (T, W, TH, 8:30-5:30)Are you ready to make a difference in the lives of patients? At Optum in the Tri-State region (formerly CareMount Medical, ProHEALTH...

Toker's Guide

Cannabis Delivery Job at Toker's Guide

 ...Toker's Guide ( tokersguide.com ( is a DC-based start-up and cannabis review site that is rapidly growing. As a part of a new growth...  ...for key positions. This description is for a DC-based cannabisdispensary that is looking for responsible delivery drivers to distribute... 

ODORZX INC.

Operations Assistant Manager (w/Washing & Detailing) 20HR-23HR Job at ODORZX INC.

 ...We are currently seeking an Operations Assistant Manager to become an integral part of our team! You will perform a variety of tasks...  ...Qualifications: Previous experience as an automotive technician, detailer, or other related fields preferred Microsoft office or...