CME Groupposted about 2 months ago
$91,400 - $152,300/Yr
Full-time - Mid Level

About the position

The Application Penetration Tester is responsible for performing manual application security assessments (application pentests) and communicating any findings to the Development and QA teams. Additionally, the engineer will provide application design support and security best practice guidance, in the form of consultations, to various development teams and business stakeholders. You will be working with a team of highly skilled Application Security Engineers that are responsible with the application security and security testing of CME Group’s applications and services. This is a great environment to get exposure to a wide array of technologies and progress your application security career, while providing value to CME and helping to ensure that our applications are designed and coded in a secure fashion.

Responsibilities

  • Perform manual whitebox/blackbox application penetration testing at key points in the Software Development Life Cycle for in-house or 3rd party developed software.
  • Produce detailed documentation (reports) and present the findings discovered during your security assessments to our stakeholders (Management, Development).
  • Provide application security consulting services at critical points in the SDLC.
  • Have an interest in continuing your education and staying current within the application security domain.

Requirements

  • 4+ years’ experience performing blackbox and/or whitebox application penetration testing (Web, APIs, Mobile, Thick clients).
  • Advanced skills with application security testing tools such as: Burpsuite, OWASP ZAP, SQLMap, IDA Pro, Kali, etc.
  • Knowledge on how to perform manual application source code security reviews for various languages such as: Java, .Net (C#, VB#), C++.
  • Experience with UNIX or Linux.
  • Experience with scripting languages such as: Python, bash, Powershell, etc.
  • Have a passion for application security, willingness to continue growing your skills in this domain, and be able to share your passion and learnings with teammates.
  • Self-motivated and a self-starter.
  • Excellent oral and written communications skills.

Nice-to-haves

  • Experience working in a DevSecOps and Continuous Integration/Continuous Delivery (CI/CD) environment.
  • Experience with Cloud (GCP) or Containers (Docker, Kubernetes).
  • Experience with micro-service architectures.
  • OSCP/OSWE, GWAPT, eWAPTx or other relevant security certifications.

Benefits

  • Comprehensive health coverage
  • Retirement package that includes both a 401(k) and an active Pension Plan
  • Highly competitive education reimbursement provisions
  • Paid time off
  • Mental health benefit
  • Annual target bonus opportunity
  • Opportunity to become an owner in the company through a broad-based equity program
Hard Skills
Docker
1
IDA Pro
1
Java
1
Kubernetes
1
Linux
1
07wJ4YLPszxc NFv6OtSY
0
0M1XPGfNdeIL h5oVaIgQ
0
4hfBrl
0
4iMmtLjgU sOqKP1w7S5gc
0
6W9ZphnvJ5yk y9ivJmQ
0
7Kna0 z36Ck8sSpRg
0
8QxO61m 8Hg07NjOclSF k7SHeEcmIOtN
0
8UiIRFc
0
8unZ3
0
9wHRUmx6L8Ys tcpzEsPuK
0
ADEWJFVri qXCVIMb
0
F1cheG3wIx XGcdeEiTRxhfv
0
GVdhjy 0y8nha6TWN
0
MIeldc04sBw 8yB1AJaqM
0
NmyXPxFTnMBV LgM5IZnPU3z
0
OmA5fJd7S RjFJg06B9f7T
0
S1Ikznr6KAp4 sEPAwGSMb
0
S43PkEoIBpy6 wMya1RPp4 SQPZxA1m
0
VL0HK9lRC CeisrWo612g3
0
a1NfJVeu8 1WxcCMd6SZHX
0
bSe7yI9 Zwgjl6d
0
dBeK6RJ8jYx72 Zj3EF8L4d7HRM
0
gXK8lbF0 xoiYUyMq82r
0
gkdEVu 0ZaQO3wx
0
opHVdnPO5N2J sm3p4MPZd B1nTxFlZ
0
pOzI0Ja
0
qwWNCTlGcRvd lIz8jD2Cx
0
tc4Qd acudJ6UKPbZ
0
vgH1SCf8Uz H2Xt 5wkYjXg8yD
0
x6rFHYS4 n9VoMb243ZrFC
0
Soft Skills
YvdzD0ZE9yRWOtlc
0
Build your resume with AI

A Smarter and Faster Way to Build Your Resume

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service