Capital One - McLean, VA

posted 3 months ago

Full-time - Principal
McLean, VA
Credit Intermediation and Related Activities

About the position

Capital One's Offensive Security team is dedicated to reducing cyber risk by identifying vulnerabilities and weaknesses within the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. The Principal Associate, Penetration Tester will work closely with team members to plan, coordinate, execute, and report on sophisticated ethical hacking exercises aimed at uncovering cyber vulnerabilities and enhancing the risk posture of enterprise systems. This role is pivotal in performing application and network security assessments, providing management with actionable recommendations for effective countermeasures. The successful candidate will thrive in a dynamic environment, contributing to the development and delivery of industry-leading ethical hacking capabilities that protect and defend the Capital One brand, systems, and data. As part of the Cyber Operations and Intelligence program, the Offensive Security team plays a crucial role in identifying opportunities to enhance Capital One's information security posture against a wide array of cyber threats, while also developing strategies to effectively address these threats. Key responsibilities include performing penetration testing on APIs, web applications, networks, and cloud services, as well as assessing Capital One's development practices to drive corporate security standards. The role also involves triaging and testing application responsible disclosure findings and newly disclosed vulnerabilities, and collaborating with developers to improve the Software Development Lifecycle (SDLC) for applications.

Responsibilities

  • Perform penetration testing of APIs, web applications, networks, and cloud services.
  • Assess Capital One's development practices and help drive corporate security standards.
  • Help triage and test application responsible disclosure findings and newly disclosed vulnerabilities.
  • Work with developers to improve the Software Development Lifecycle (SDLC) for applications.

Requirements

  • High School Diploma, GED or equivalent certification.
  • At least 4 years of experience working in cybersecurity or information technology.
  • At least 3 years of Penetration Testing experience.
  • At least 1 year of experience with public cloud environments (AWS, Azure, GCP).

Nice-to-haves

  • Bachelor's Degree.
  • 5+ years of security testing experience (red teaming, cloud security, application security, or network security).
  • 5+ years of experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE).
  • Penetration testing experience with Internet of Things (IoT) devices, mobile applications, or code review.
  • Development experience with common scripting/programming languages such as Python, Golang, and C#.

Benefits

  • Comprehensive health benefits including medical, dental, and vision insurance.
  • 401(k) retirement savings plan with company matching.
  • Performance-based incentive compensation, including cash bonuses and long-term incentives.
  • Flexible work arrangements including hybrid on-site options.
  • Tuition reimbursement for further education.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service