Security Assurance Penetration Tester
$71.6k - $119.4kElsevier
Collaborative Penetration Tester
Are you a collaborative penetration tester looking to work for a mission driven global organization?
Role Overview
This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment.
Team Overview
The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.
Responsibilities
- Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
- Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
- Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
- Maintaining program documentation, test records, and reporting artifacts.
- Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
- Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
- Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
- Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
- Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
- Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
- Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
- At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
- Foundational understanding of web application architecture, networking, and operating system security.
- Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
- Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
- Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
- Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
- Exposure to SAST/DAST tools and secure code review practices is desirable.
- Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)
Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.
Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer-reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.
In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements.
U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates.
Application deadline is 09/17/2026.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact View phone number on click.appcast.io.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
- ...Requirements 5 or more years of experience in software quality assurance, system testing, and test automation. Proficiency in test automation frameworks, C# or Java programming, and DevOps integrations. Experience with testing web services using SoapUI...Suggested
- ...preferred. Required Qualifications: Five (5) or more years of Quality Assurance experience testing large enterprise applications. Strong... ..., testing processes, and quality best practices. Mentor junior testers and share knowledge of testing methodologies and automation best...Suggested
- ...Title: QA Tester Location: Hartford CT On-site/Remote/Hybrid: REMOTE Duration: 12 Months Interview Process: Webcam... ...with the current versions of both the state and federal CJIS Security Policies. Governor Lamont has stated that the CJIS Governing Board...SuggestedRemote work
- ...Security Engineer Role: Security Engineer (Java, LDAP, Radiant One VDS) Location: Hartford, CT 1. Basic knowledge of HDAP, RadiantOne ICS and FID products 2. Expert in core Java and LDAP and AD 3. Understanding of databases and other data stores 4. Experience...Suggested
$112.5k - $202.5k
...Do you like building solutions to help improve the security of the company? Do you want to collaborate with industry-leading security experts? Join our Information Security Team! Akamai's Information Security team is responsible for safeguarding Akamai, its customers...SuggestedWork experience placementWork at officeWorldwide- ...Senior Security Engineer Architect Data Protection and DLP Develop and apply security & privacy best practices into all projects that collect, store, and disseminate consumer data. Closely work along with Architects from our Data Visualization, Data Analytics, Data...
$40k
...Maximus is a trusted federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining, operating, and improving essential government systems and services, with proven operational excellence...Contract workRemote work$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you’ll collaborate...Work at officeRemote work- ...Technology, exposure to programming in 3rd generation languages and knowledge of software design patterns 5 to 7 years of experience as a tester for IT projects Experience in NIEM XML or another complex XML Standard Experience with testing web services manually using Soap UI...Contract workMonday to Friday
- ...Senior Product Security Engineer The Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Product Security function at CBIZ. As the first dedicated hire in this domain, this...
$84.63k - $112.84k
...AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities. At Lumen, you’ll...Contract workTemporary workRemote work- ...environments - Strong attention to detail and ability to work in structured, compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic monitoring - Experience or exposure to vulnerability management,...Minimum wageContract workTemporary workWork experience placementRemote work
$141.2k - $278.3k
Position Summary Google Infrastructure and Security Lead ArchitectJoin our AI & Engineering team in transforming technology platforms, driving innovation, and helping make a significant impact on our clients' success. You’ll work alongside talented professionals...Local areaVisa sponsorshipFlexible hours$40 - $55 per hour
...Job Title: Application Tester - Remote Duration (Contract): 12 Months Client Location: Hartford, CT 06107 Location Preference... .... ~5-7 years of experience in software testing, quality assurance, and enterprise application validation. ~ Experience...Hourly payContract workRemote work$128.4k - $192.6k
Senior Security Engineer - IS07FEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too....Full timeTemporary workWork at office3 days per week$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll... ...governance, risk management, dependencies, and quality assurance for enterprise security transformationsAbility to travel 25-50%...Local area$250.6k - $362.6k
...received.This is a fully remote opportunity open to candidates located anywhere in the United States.Meet the Team You will join Cisco’s Security and Policy Platform Group, a foundational organization responsible for transforming Cisco’s Security products from single point...Full timeTemporary workLocal areaRemote workFlexible hours$150k - $165k
...our Client Centric, Risk Centric, and Technology Centric strategies. Built to be resilient, Ascot offers clients leading financial security while delivering bespoke products and world class service — both pre- and post-claims. Ascot exists to solve for our clients’...Temporary workWork at officeLocal areaFlexible hours- ...Job Title: UAT Tester(Child Support) Location: Hartford CT Duration: Long Term... ...execution, defect validation, and quality assurance. The successful candidate will work... ...Must comply with all State policies, security requirements, and procedures. Preferred...Local area
$84.91k - $113.91k
...Overview Your Future. Secured. ISC2 is a force for good. As the world's leading nonprofit member organization for cybersecurity professionals, our core values - Integrity, Advocacy, Commitment, Inclusion, and Excellence - drive everything we do in support of our vision...Work experience placementWork at officeRemote workNight shift- ..., in the cloud, or through a hybrid approach. Teradata delivers real business value with AI. What You’ll Do The Application Security integrates and support security at every phase of the software development lifecycle (SDLC) and work closely with developers to ensure...Permanent employmentFlexible hoursShift work
- IT Project Manager We are seeking an experienced IT Project Manager with a proven track record in managing complex projects, particularly those involving the migration of on-premises infrastructure to the cloud. The ideal candidate will possess strong communication ...For subcontractor
$82.6k - $162.8k
...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation. Non-human identities (NHIs) include service accounts,...Local areaVisa sponsorship$134.5k - $265.1k
...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs an Engineering Manager II on the Deloitte Cyber team, you will...Local areaVisa sponsorship$155.6k - $306.8k
Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity, access, and data protection challenges through AI-enabled engineering solutions. This role sits at the intersection of ...Local areaVisa sponsorship- ...continuously works to enhance system performance, security, and operational efficiency.Position... ...seeking two experienced QA Automation Testers to support testing activities for... ...operations teams to ensure robust quality assurance processes.Key ResponsibilitiesDevelop and...Monday to Friday
$155.6k - $306.8k
...landscape. We simplify complexity, and enable businesses to operate with resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.Work you will do:As a Cyber Forward Deployed Engineer (FDE) Manager, you will...Local areaVisa sponsorship$100k - $120k
...testing, and documentation Integrations and issue resolution across HRIS, payroll, and related platforms Compliance, privacy, and security standardsSuccess in this role requires strong UKG Pro WFM experience, a solid understanding of workforce processes, and a background...$105.4k - $207.8k
...Cyber practice as a Cyber SecOps Senior Consultant and help clients navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat...Local areaVisa sponsorship$97.61k - $188.38k
...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll doAs Identity and Access Management (IAM) solutions team Saviynt...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Assurance Penetration Tester. Be the first to apply!


