Security Assurance Penetration Tester
$71.6k - $119.4kRELX Group
Are you a collaborative Penetration Tester looking to work for a mission driven global organization?About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment.About the team - The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.ResponsibilitiesTracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.Maintaining program documentation, test records, and reporting artifacts.Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.RequirementsExperience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.Foundational understanding of web application architecture, networking, and operating system security.Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.Exposure to SAST/DAST tools and secure code review practices is desirable.Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer-reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements. U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates. If performed in Colorado, the base pay range is $71,600 - $119,400.If performed in New York, the base pay range is $78,700 - $131,400.If performed in New York City, the base pay range is $85,900 - $143,300.If performed in Rochester, NY, the base pay range is $71,600 - $119,400.If performed in New Jersey, the base pay range is $84,546 - $135,054. This job is eligible for an annual incentive bonus. Application deadline is 09/17/2026. We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact View phone number on click.appcast.io.Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.Please read our Candidate Privacy Policy.We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.USA Job Seekers:EEO Know Your Rights.SummaryLocation: Pennsylvania; Connecticut; Virginia; Massachusetts; Home Based - Pittsburgh, PA; Delaware; Michigan; New Jersey; Philadelphia; Colorado; New YorkType: Full time
$80k - $120k
Sonalysts, Inc. is seeking an Information Systems Security Officer (ISSO) for our Waterford, CT office. What you will be doing:Advise... ...Information Systems security experienceHold a current DOD Information Assurance Workforce (IAWF) Level II (or higher) IAM or IAT certification...SuggestedFull timeWork at officeLocal areaFlexible hours- ...Job Title: QA Tester Client: State of CT Department: Department of Children and Families... ...the service of 1, HANDS ON, Quality Assurance Automated Tester. The specific focus of... ...scalability, extensibility, maintainability, security, interoperability) for now and for the...SuggestedContract workShift work
$104k - $156k
Posting Type Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational... .... Required Skills: Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation,...SuggestedRemote work$128.4k - $192.6k
Senior Security Engineer - IS07FEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too....SuggestedFull timeTemporary workWork at office3 days per week- Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting... ...analysis. The ideal candidate will possess proficiency in penetration testing methodologies and platforms, scripting and programming...SuggestedFull timeWork experience placementLocal areaRemote work
$40 per hour
...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback... ...~2+ years of hands‑on experience in cybersecurity (e.g., penetration testing, red teaming, incident response, detection engineering...Hourly payFull timePart timeRemote work- Infosys Limited is seeking a QA/Software Testing professional within its Healthcare unit to transform healthcare delivery through AI-driven solutions. The role involves end-to-end SDLC participation, documentation of requirements, design discussions, coding support, and...
- ...Field CTO to enhance client engagements by providing expert guidance on IT cybersecurity and compliance, while engaging directly with security leaders. The role involves around 30-40% travel and responsibilities covering security frameworks, customer advisory, and internal...
- ...Technologist in Hartford, Connecticut. You will engage with third parties to assess cybersecurity risks and provide operational support for security processes. The ideal candidate will have a Bachelor's Degree in a STEM field, five years of relevant cybersecurity experience, and...
- ...Maximus is seeking a Security Compliance Architect in Hartford, Connecticut. This role involves providing technical leadership in designing secure IT systems and ensuring compliance with cybersecurity standards. Candidates must hold a Bachelor’s degree and have over 1...
- ...and defect management across OT environments. You will supervise architecture oversight, track issues, and ensure alignment with security and regulatory requirements. You will collaborate with OT architects, cybersecurity, and product teams to resolve defects and drive...
$90k - $120k
...Audit team. This high-visibility role will focus heavily on IT Security, alongside infrastructure and SOC 2 audits, offering the... ...Senior Management.Key Responsibilities: • Deliver risk-based assurance and advisory reviews in accordance with department professional...$144.9k - $265.8k
...consolidations and hybrid identity programs. ~ Translating business, security and regulatory needs into practical identity architecture,... .... EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector...Full timeSummer holidayFlexible hours- ...intelligent insights. The RolePresidio is seeking Network and Security Practice Leads, in Boston MA. These individuals will be hands-on... ...engagements. The role will require overseeing a team of engineers, assuring that both Presidio and vendor best practices are adhered to, as...Full timeFor contractorsLocal area
$105.4k - $207.8k
...Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that modernize client security... ...industry certifications such as Security+, Global Information Assurance Certification Security Essentials, Global Information Assurance...Local areaVisa sponsorship- Securitas Technology, part of Securitas, is a world-leading provider of integrated security solutions that protect, connect, and optimize businesses of all types and sizes. More than 13,000 colleagues in 40 countries are focused daily on our purpose to help make your world...Hourly payTemporary workFor contractorsFor subcontractor
$141.2k - $278.3k
Position Summary Google Infrastructure and Security Lead ArchitectJoin our AI & Engineering team in transforming technology platforms, driving innovation, and helping make a significant impact on our clients' success. You’ll work alongside talented professionals...Local areaVisa sponsorshipFlexible hours- ...environments - Strong attention to detail and ability to work in structured, compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic monitoring - Experience or exposure to vulnerability management,...Minimum wageContract workTemporary workWork experience placementRemote work
$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll... ...governance, risk management, dependencies, and quality assurance for enterprise security transformationsAbility to travel 25-50%...Local area$250.6k - $362.6k
...received.This is a fully remote opportunity open to candidates located anywhere in the United States.Meet the Team You will join Cisco’s Security and Policy Platform Group, a foundational organization responsible for transforming Cisco’s Security products from single point...Full timeTemporary workLocal areaRemote workFlexible hours$150k - $165k
...our Client Centric, Risk Centric, and Technology Centric strategies. Built to be resilient, Ascot offers clients leading financial security while delivering bespoke products and world class service — both pre- and post-claims. Ascot exists to solve for our clients’...Temporary workWork at officeLocal areaFlexible hours$218.7k - $267.3k
...formerly known as Twitter) @BookingHoldings.This role is eligible for our hybrid work model: Two days in-office.The Global Sr Enterprise Security Architect (Director level) is a high-impact, strategic leadership role responsible for the long-term security enterprise...Full timeWork at officeLocal areaImmediate start- Responsibilities Support Gartner’s AppSec function. Execute daily vulnerability Assessments functions. Collaborate with Information Security partners and technology stakeholders to identify risks/vulnerabilities. Remediation planning and coordination for security...
$103.2k - $154.8k
...testing, Service virtualization, Enterprise data and data quality assurance in addition to helping the organization move towards... ....· Provide solutions to shift-left NFR testing - performance, security and accessibility for external facing digital applications.· Identify...Full timeTemporary workWork at officeHome officeShift work3 days per week$142.6k - $261.5k
...manage the delivery of technology transformation projects and programs that align with our organizational strategy. You will provide assurance to leadership by managing timelines, costs, and quality, while leading both technical and non-technical project teams in the...Full timeSummer holidayFlexible hours- ...Senior Application Security Engineer The Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Application Security function at CBIZ. As the first dedicated hire in this...
$134k - $171k
...sophisticated and dynamic systems that create facility environments—such as electrical, mechanical, lighting, air conditioning, heating, security, fire protection, and power generation systems—in virtually every sector of the economy and for a diverse range of businesses,...Full timeRemote workFlexible hours$82.6k - $162.8k
...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation. Non-human identities (NHIs) include service accounts,...Local areaVisa sponsorship$150k - $180k
...helping the organization enhance its overall security posture and compliance framework. You’... ...the SME for cybersecurity, including penetration testing, firewalls, networks, etc. •... ...technology risk, cyber consulting, cyber assurance, or IT audit, with a significant focus...Flexible hours$500 per month
...Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements:...Remote work10 hours per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Assurance Penetration Tester. Be the first to apply!

