Penetration Tester
$100k - $140kNBCUniversal
Base pay range
$100,000.00/yr - $140,000.00/yr
Company Overview
NBCUniversal is a leading media and entertainment company that distributes content across film, television, streaming and theme parks. It owns brands such as NBC, NBC News, NBC Sports, Telemundo, Peacock, Universal Pictures, DreamWorks Animation, and operates Universal Studios Hollywood and Or. The company values diversity, inclusion, and community impact.
Job Title
PCI Scanning & Penetration Testing Coordinator – Cyber Governance Risk and Compliance
Job Description
The Cyber Governance Risk and Compliance team is seeking a PCI Scanning & Penetration Testing Coordinator to lead and manage the organization’s PCI ASV scanning and penetration testing programs. This role serves as the central liaison between internal business units, technical teams, and external vendors, while also possessing the technical capability to conduct penetration tests independently when required. The successful candidate will ensure timely execution, remediation, and compliance with PCI DSS requirements across all business entities.
Responsibilities
- Managing and maintaining PCI ASV scan schedules across all business units.
- Initiating and tracking ad hoc scans, ensuring timely execution and reporting.
- Validating remediation of vulnerabilities and special notes, coordinating with technical teams and GRC.
- Acting as the single point of contact for the ASV vendor, resolving anomalies and portal issues.
- Negotiating false positives and scan disputes with the vendor on behalf of business units.
- Coordinating annual and ad hoc PCI penetration tests across applicable environments.
- Scoping, scheduling, and executing penetration tests internally when vendor support is unavailable or impractical.
- Performing manual and automated testing techniques including network, web application, and system-level assessments.
- Analyzing test results, documenting findings, and providing remediation guidance aligned with PCI DSS.
- Tracking remediation efforts and maintaining centralized documentation of test reports and compliance evidence.
- Generating and maintaining reports for internal stakeholders, auditors, and compliance attestations.
- Interfacing with business unit technical teams to ensure understanding and prioritization of findings.
- Providing guidance and support to teams with limited PCI knowledge or bandwidth.
Qualifications
- Bachelor’s Degree in an IT-related field and/or equivalent work experience.
- Minimum 3–5 years of experience in PCI compliance, vulnerability management, or penetration testing.
- Strong understanding of PCI DSS requirements, especially ASV scanning and penetration testing controls.
- Proficiency in penetration testing methodologies (OWASP, NIST SP 800-115, PTES).
- Experience with tools such as Burp Suite, Nmap, Nessus, Metasploit, Kali Linux, and scripting (Python, Bash).
- Working knowledge of network protocols, web application architecture, and common vulnerabilities.
- Experience working with external vendors and internal technical teams.
- Excellent organizational, communication, and documentation skills.
- Ability to manage multiple concurrent projects and deadlines.
- Certifications (at least one Required):
- Offensive Security Certified Professional (OSCP)
- GIAC Penetration Tester (GPEN)
- Certified Ethical Hacker (CEH)
- Certifications (Preferred):
- PCI Internal Security Assessor (ISA)
- GIAC Web Application Penetration Tester (GWAPT)
- CISSP or CISM for broader security leadership alignment
Additional Requirements
- Fully Remote: This position is designated as fully remote, meaning the employee may work from home or a remote location.
Benefits
This position is eligible for company-sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website.
Additional Information
NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing View email address on click.appcast.io.
For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
#J-18808-Ljbffr- ...Penetration Tester Our client is seeking a Penetration Tester with 8-10 years of experience to review and validate vulnerability reports, perform targeted retesting, and coordinate remediation efforts across development and infrastructure teams. Responsibilities...Suggested
- ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and... ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive...Suggested
- ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and... ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive...Suggested
$85k - $100k
: Paramount is hiring a Vulnerability Analyst to join its Vulnerability Management Team. The position is responsible for supporting the Information Security organization's efforts to manage vulnerabilities in all global Paramount systems, including those supporting streaming...SuggestedFull timeInternshipWorldwide$120k - $140k
...vulnerability management lifecycle ~ Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability ~ Proactively identify systemic risks and facilitate cross-functional...SuggestedTemporary workWork at officeImmediate startRemote workWork from home$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$220k - $260k
Who We Are Notion is the collaborative AI workspace where teams and agents think together. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work feels faster, clearer, and less fragmented. Millions of individuals,...Work at officeLocal area- Digital Forensics Analyst We are seeking a detail-oriented and analytical Digital Forensics Analyst to investigate cyber incidents, collect and preserve digital evidence, and perform forensic analysis across computers, mobile devices, cloud platforms, and networks. ...
- Digital Forensic Analyst CGS is seeking a Digital Forensic Analyst whose primary focus will be on the preservation & collection of mobile device and cloud-stored data. This candidate should be fluent in a broad range of forensic technologies and interested in taking...Work at officeRemote workFlexible hours
- Job Description: Digital Forensics Specialist Position Title Digital Forensics Specialist Job Summary We are seeking a skilled Digital Forensics Specialist to conduct forensic investigations, collect and analyze digital evidence, and support...Full timeContract work
- ...issues - Support secure development practices for in-house applications - Assist with annual security assessments, including: - Penetration Testing - Vulnerability Assessment - IT Risk Assessment Requirements - Must be authorized to work in U.S. -...
- Security Engineering Role We believe that the way people interact with their finances will drastically improve in the next few years. We're dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their...Work experience placementLocal area
- Job Description Job Description Position Summary: This position requires a candidate that can commute to Long Island on a daily basis. Well established Manufacturing company, in business since 1951, is seeking a self motivated, team player, to focus on the following...
- Job Title Required Skills: ~10-12+ years of QA engineering experience, with a strong track record in Agile SDLC teams, ideally working with CI/CD pipelines. ~ Experience in the financial domain a plus. ~ Proficiency in Java programming, with a focus on Behavior...
- Vice President Information Security Officer This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week. This role is for Vice President level candidates. Sumitomo Mitsui Trust Bank, Limited was established...Work at officeWork from homeFlexible hours2 days per week
$270k - $320k
...Experience in information security leadership roles with a strong hands-on technical background (e.g., security engineering, penetration testing, cloud security architecture, or incident response). Expertise in risk management, operational risk frameworks, vendor...Work at officeFlexible hours3 days per week$300k - $350k
...Engineering leadership to embed security into the product development lifecycle. ~ Lead teams conducting threat modeling, penetration testing, red-teaming, and incident response programs. ~ Set and communicate security policy to the board and executive...Odd jobWork at officeImmediate startRelocation package- Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We're training and deploying frontier models for enterprises who are...Full timeWork at officeLocal areaRemote workHome office
$180k - $225k
Information Security Officer Sompo has a unique opportunity for an Information Security Officer to join our Information Security team. This role will manage and continuously modernize our Information Security program for global operations, while maintaining alignment...Full timeFor contractorsWork at officeFlexible hours$150k - $200k
Chief Information Security Officer (CISO) Vistrada is looking to hire strong Chief Information Security Officers (CISO). The CISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity programs to help...Work experience placementRemote workFlexible hours- Company Description As the world's leading vendor of Cyber Security, facing the most sophisticated threats and attacks, we've assembled a global team of the most driven, creative, and innovative people. At Check Point, our employees are redefining the security landscape...
- Socure is seeking a Senior SDET to advance our quality engineering for distributed systems, DR, and production readiness. You will design automated health checks, build end-to-end validation pipelines, and develop AI-driven failure analysis to reduce incident response ...
- Role: - SDET Location: - 30 Rockefeller, NY Duration: - Long term contract Job Description: Looking for 12+ Years of Experience What are the top 3 Must Haves for this role? 1. Java & JS automation for web 2. QE experience - 10+ Years...Long term contract
- Purple Drive Senior SDET Share Contractual New York, NY Overview: The SDET (Software Development Engineer in Test) is responsible for ensuring the quality and reliability of ETL processes and data integration workflows. This role involves designing and implementing...
- ...continuous improvement of security capabilities. Vulnerability & Threat Management Manage vulnerability assessment and penetration testing programs. Prioritize vulnerabilities based on business risk and impact. Ensure remediation activities are tracked...Full timeContract work
- Mercor is seeking experienced Software Engineers, QA Engineers, SDETs, and Test Automation Engineers to review browser-based evaluation workflows for AI-generated web applications. You will validate that browser tests are deterministic and capable of producing clear...
- ...graduation or post-graduation. ~3+ years of related work experience. Required skills: Selenium, API, Automation, Javascript. Basic qualification: Additional skills: UI Designer, QA Analyst, Quality Engineer, QA / Tester. This is a high priority requisition....Work experience placement
- Why Socure? Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments...Shift work
$135.72k - $169.65k
Join Brex Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders...Work at officeRemote workWork from home- Systems Analyst The New York City Department of Youth and Community Development (DYCD) invests in a network of community-based organizations and programs to alleviate the effects of poverty and to provide opportunities for New Yorkers and communities to flourish. DYCD...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!


