Summary
Verizon is a telecommunications company focused on connecting people and enabling how they live, work, and play. The Security Engineer will support the Dynamic Application Security Testing team by building automated security testing tools and processes, performing ethical hacking and penetration testing, and supporting bug bounty and critical incident response efforts.
Responsibilities
- Integrating dynamic analysis tools (OWASP ZAP, Burp Suite) directly into Jenkins and GitLab CI/CD pipelines to ensure continuous security testing
- Writing and maintaining custom automation scripts using Python, Java, and Bash to scale our security efforts and eliminate manual bottlenecks
- Utilizing AI to build new testing capabilities, streamline the triage of bug bounty submissions, and troubleshoot code across our tech stack
- Deploying, hosting, and maintaining containerized security testing environments using Docker and AWS
- Partnering with engineering teams to guide them through identifying and remediating OWASP Top 10 vulnerabilities
- Leveraging your offensive expertise to triage incoming bug bounty submissions and support Verizon's critical incident response efforts
- Performing ethical hacking and penetration testing against web applications, mobile apps, and APIs to uncover vulnerabilities before malicious actors do
Skills
- Bachelor's degree or one or more years of work experience
- 2+ years of hands-on experience in Application Security, Penetration Testing, or a DevSecOps engineering role
- Deep understanding of web application architecture, APIs (REST/GraphQL), and mobile application security
- Comprehensive knowledge of the OWASP Top 10, CWEs, CVSS scoring, and how to manually validate and exploit these vulnerabilities
- Proficiency operating and configuring industry-standard dynamic analysis tools, specifically Burp Suite Professional and OWASP ZAP
- Proven experience integrating security tools into modern CI/CD pipelines using Jenkins and GitLab CI
- Strong ability to read, write, and maintain automation scripts in Python and Bash
- Hands-on experience working with Docker containers and deploying/managing applications in AWS (experience with EC2s/Linux is a plus)
- Ability to clearly explain complex security vulnerabilities (and why remediating them is important) to software engineers who may not have a security background
- Experience using AI assistants (ideally Gemini or Claude Code) for scripting, debugging code, or day to day productivity improvements
Qualifications
Must Haves
- Bachelor's degree or one or more years of work experience
Nice to Haves
- 2+ years of hands-on experience in Application Security, Penetration Testing, or a DevSecOps engineering role
- Deep understanding of web application architecture, APIs (REST/GraphQL), and mobile application security
- Comprehensive knowledge of the OWASP Top 10, CWEs, CVSS scoring, and how to manually validate and exploit these vulnerabilities
- Proficiency operating and configuring industry-standard dynamic analysis tools, specifically Burp Suite Professional and OWASP ZAP
- Proven experience integrating security tools into modern CI/CD pipelines using Jenkins and GitLab CI
- Strong ability to read, write, and maintain automation scripts in Python and Bash
- Hands-on experience working with Docker containers and deploying/managing applications in AWS (experience with EC2s/Linux is a plus)
- Ability to clearly explain complex security vulnerabilities (and why remediating them is important) to software engineers who may not have a security background
- Experience using AI assistants (ideally Gemini or Claude Code) for scripting, debugging code, or day to day productivity improvements
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- Short-term disability insurance
- Long-term disability insurance
- Basic life insurance
- Supplemental life insurance
- AD&D insurance
- Identity theft protection
- Pet insurance
- Group home and auto insurance
- Matched 401(k) savings plan
- Up to 8 company-paid holidays per year
- Up to 6 personal days per year
- Paid parental leave
- Adoption assistance
- Tuition assistance
- Premium pay such as overtime, shift differential, holiday pay, and allowances, depending on the role
- Newly hired employees receive up to 15 days of vacation per year, which grows with additional service
- Remote work from home with occasional in-person trainings and meetings