Security Assurance Penetration Tester
$71.6k - $119.4kRELX
Pennsylvania
Connecticut
Virginia
Massachusetts
Home Based - Pittsburgh, PA
Delaware
Michigan
New Jersey
Philadelphia
Colorado
New York
Full time
R115215
Are you a collaborative Penetration Tester looking to work for a mission driven global organization?
About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment.
About the team - The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.
Responsibilities
Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
Maintaining program documentation, test records, and reporting artifacts.
Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
Foundational understanding of web application architecture, networking, and operating system security.
Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
Exposure to SAST/DAST tools and secure code review practices is desirable.
Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)
Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.
Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer-reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.
In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements.
U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates.
If performed in Colorado, the base pay range is $71,600 - $119,400.If performed in New York, the base pay range is $78,700 - $131,400.If performed in New York City, the base pay range is $85,900 - $143,300.If performed in Rochester, NY, the base pay range is $71,600 - $119,400.If performed in New Jersey, the base pay range is $84,546 - $135,054.
This job is eligible for an annual incentive bonus.
Application deadline is 09/17/2026.
We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here ( to access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact View phone number on click.appcast.io.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
EEO Know Your Rights.
RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.
Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.
Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
$85k - $141k
...Clearance Required : Ability to Obtain Public Trust The Quality Assurance System Tester will support a large-scale agile software development... ...existing system capabilities meet functional, technical, security, accessibility, and operational requirements before production...SuggestedContract workTemporary workFlexible hours$137.6k - $184k
- Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across... ...to customer sites as needed.About the teamThe AWS Security Assurance Services team, within AWS Support, leverages the expertise and...SuggestedInternshipFlexible hours- ...Description Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence... ...assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security...Suggested
- P-1528As a Staff Security Assurance Engineer within the Security Assurance Team, you will help lead high-visibility security compliance implementation initiatives. Reporting directly to the Senior Director, you will serve as a strategic catalyst for these programs, ensuring...SuggestedWorldwideRelocation
$90k - $155k
...together with our customers to tackle the most complex national security challenges. For more than 20 years we've supported critical... ...and AFDW-approved systems and tools. Maintain and support Assured Compliance Assessment Solution (ACAS) capabilities and ensure vulnerability...SuggestedContract workRemote workFlexible hours$130k - $190k
At Battelle, your expertise in national security plays a direct role in safeguarding our nation and shaping global security strategies... ...stability worldwide.Job SummaryWe are currently seeking a Penetration Tester. This position is a full-time opportunity located in...Full timeWork experience placementWork at officeLocal areaRemote workWorldwideFlexible hours- .... We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$5,000 per month
...Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated... .... Derive, document and/or identify system CONOPS for Mission Assurance Categorization per DoDI 8500.2. Research and recommend logical...Work at office$86k - $138k
...Peraton is currently seeking to hire a Cybersecurity Analyst - Security Standards & Baselines to become part of our Federal Strategic... ...rigorous application of information security and information assurance policies and practices.Evaluate existing, emerging, and modified...Contract workCurrently hiringWork at officeShift work$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal and Global Communications and Community Impact (GCCI) business units.Our Mission is to protect and safeguard...InternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering... ...vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience...InternshipFlexible hoursShift work$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$107.93k - $188.9k
Position Summary Deloitte’s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM...Remote work- ...And Exercises Vice President Drive the security of critical banking applications and... ...will be to plan, execute, and report on penetration tests targeting high-impact applications... ...penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up...
$153.6k - $207.8k
...ProServe) team is seeking a skilled Senior Delivery Consultant - Security to join our team at Amazon Web Services (AWS). In this role,... ...and Managed Services, and meet objectives with AWS Security Assurance Services. Our expertise and emerging technologies include AWS...Flexible hours- ...career while leaving a lasting legacy.Position Summary:The Defense Security Cooperation Agency (DSCA) Program, Analytical, Technical, and... ...improvement, data and resource management, quality control/assurance, and subject-matter expertise in security cooperation...Contract workFor contractorsWork at officeWorldwide
$5,000 per month
...One Technology & Management, Ltd. is seeking four (4) Senior Security Systems Engineers with specific experience working with Submarine... .../or identify system Concept of Operation (CONOPS) for Mission Assurance Categorization per DoDI 8500.2. Lead the research, recommend...Interim role- ...contractor that provides services and solutions in: National Security Programs Professional, Administrative, and Management... ...points, (and other web-related assets) using both Information Assurance & Cybersecurity Division (IAD)-provided automated testing tools...Full timeFor contractors
- ...contractor that provides services and solutions in: National Security Programs Professional, Administrative, and Management... ...mobile application code and conduct testing using both Information Assurance & Cybersecurity Division (IAD) automated testing tools and...Full timeFor contractors
- ...delivering Information Technology, Information management, Information Assurance (IA) and cybersecurity solutions to US Federal Government and... ...investigations. This position ensures the availability, security, and forensic integrity of systems, tools, and infrastructure...
$125k - $145k
...Perform network and media digital forensic investigations to support cybersecurity incident response, threat analysis, and enterprise security operations. Conduct advanced threat hunting activities across enterprise infrastructure to identify malicious activity, indicators...Full timeContract workFlexible hours2 days per week3 days per week$101k - $152k
...Applied Information Sciences, Inc in Alexandria, Virginia is seeking a Senior Security Engineer to conduct comprehensive digital forensic examinations across various systems. This role includes responsibility for incident management, malware analysis, and deep investigations...Contract work- ...concepts or Pega functional testing tools (coursework, training, or internship experience acceptable). Basic understanding of Quality Assurance principles such as test case creation, defect reporting, and regression testing. Ability to read and interpret requirements or...Internship
- ...Hands on experience with Pega functional testing tools and QA testing approaches for Pega applications. Strong foundation in Quality Assurance principles, test case development, defect tracking, and regression testing. Ability to analyze requirements and translate them...
$104k - $166k
...Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver...Full timeContract workTemporary workInterim roleCurrently hiringWork at officeLocal areaShift work$86k - $138k
Overview Cybersecurity Analyst - Security Standards & Baselines / Active Secret Job Locations US-VA-Arlington Requisition Requisition... .... Ensure rigorous application of information security and assurance policies and practices. Evaluate existing and emerging technologies...Contract workWork at officeShift work$110.18k - $183.63k
...to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Information Systems Security Officer (ISSO) to join our team in Arlington, Virginia (US-VA), United States (US).Job Summary:The Information Systems Security...Full timeTemporary workWork at officeRemote workFlexible hours- ...contractor will apply knowledge and understanding of information assurance (IA) concepts and practices. and procedures using established... ...DIA policies and standards to minimize and/or mitigate RMF security risks.The contractor will review and comment on technical documentation...For contractorsWork experience placementFor subcontractorWorldwide
$107.9k - $195.05k
Job DescriptionInformation Systems Security Officer (ISSO) Leidos - Cyber & Analytics Business Area, Key Management & Analytics Division... ...information our customers depend on—supporting information assurance, security operations, system accreditation, configuration management...Full timeImmediate startRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Assurance Penetration Tester. Be the first to apply!


