Urbane Security logo
Urbane Security
Posted 75 days agoVerified live 1d ago

Senior Associate - Penetration Testing - Chicago, IL or Remote, USA

Brief overview

Remote
$125k–$195k/yrStated range
4+ yrsMinimum
Penetration TestingExternal Network Penetration TestingInternal Network Penetration TestingWireless Penetration TestingWeb Application Penetration TestingMobile Application Penetration TestingIOT Device Penetration TestingPhysical Security TestingOperating SystemsNetwork HardwareWeb Application LanguagesAuthentication MechanismsCloud PlatformsMetasploitBurp SuiteNmapRuby

About the company

Urbane Security logo
Urbane Securityurbanesecurity.com

Urbane Security is a company that creates network security for Fortune 500 companies.

Job description

Summary

Urbane Security is an information security firm focused on elevating the level of security and compliance through uniquely tailored highly-technical engagements. They are seeking a Senior Associate in Penetration Testing to assess security weaknesses in various technical environments and provide remediation suggestions.

Responsibilities

  • Assess real-life risks to diverse technical environments by identifying security weaknesses, actively exploit their findings, and determine additional impact through post exploitation
  • Face diverse challenges including black box network testing, insider threat assessments, credentialed application exploitation, and testing the effectiveness of human and physical controls
  • Provide guidance on defensive designs or assisting compliance associates on difficult technical choices
  • Improving environments security
  • Advising teams on the most effective ways to address the core security problems
  • Address real security problems

Skills

  • 4+ years of experience in penetration testing, either consulting or internal
  • Performed one or more of the following roles as a penetration tester: external network penetration testing, internal network penetration testing, wireless penetration testing, web application penetration testing, mobile application penetration testing, IOT device penetration testing, non-destructive physical security testing
  • Gained a strong technical knowledge and understanding of mixed-technology environments, include diverse operating systems, network hardware, web application languages, administration technologies, authentication mechanisms, and cloud platforms
  • Extensively used open source penetration testing tools and frameworks, such as (but not limited to) Metasploit, Burp, Nmap, etc
  • Developed or modified tools in scripting languages, such as Ruby, Python, GoLang, Perl, or Java, to assist in testing a problem
  • Learned the core fundamentals of computers, all the way down to protocol stacks
  • Paid enough attention in English class to write good (or is it well?) and know to self-QA deliverables before sending them to others
  • Creative, out-of-the-box thinker who can leverage various domains of knowledge to create uniquely tailored tests and solutions for complex problems
  • You're curious by nature, intrigued by how things work, and have an appetite to find weaknesses in their design and implementation
  • You prefer building, contributing, and leading over falling in line
  • You're happy to put in the extra effort building a tool that makes everyone's lives easier
  • Urbane team members value developing long-term client relationships over “drop the mic” moments. You want to provide remediation suggestions that address the core issues, are sustainable, and work within the confines of the target environment
  • You're passionate about technology and find entertainment in crazy personal projects (i.e., programming a USB Nerf gun and webcam to mess with your cat while you aren't at home, building an enterprise-grade virtualization environment in your bedroom closet, or seeing how many neighbors think your “free” wifi is actually “free”)
  • A desire to stay current with the latest technologies, attacks, and hardening strategies. You're a regular online reader of blogs and social media for the latest in security, enjoy good conference talks, and/or contribute to interesting projects
  • Driven personality, with a desire to continuously improve, put in the hours, and deliver. You take pride in your work, and you want it to be the best you can do
  • Not opposed to traveling and can survive occasions requiring Domestic/International travel (currently less than 25%, but subject to fluctuate)
  • Highly organized and detail-oriented with the ability to independently prioritize multiple projects while still balancing personal goals. You recognize when you need help, and aren't afraid to ask for it
  • Have a strong ethical compass and an understanding of ethics in business and information security. You'll respect scope limitations, clean up after your attacks, and never access or retain data that isn't pertinent to the testing
  • Equally comfortable holding your own with a technical audience (especially the Unix-Beards) as well as communicating to a non-technical audience (including the C-Suite), both in writing and verbally
  • Maintain a unique and independent identity, but respect other business' culture, including dress apparel, level of formality, and work schedules. We maintain a startup-style culture internally, while presenting a clean, elevated, and refined image to the rest of the world
  • Currently a US citizen or other permanent US resident
  • College or equivalent educational experience
  • Have fun acronyms after your name, such as OSCP, OSWP, GPEN, GWAPT, CPTE, CISSP, or are not opposed to getting them as needed
  • Experience in modifying or creating tools or payloads to exploit vulnerabilities not effectively covered in other exploitation frameworks
  • Have performed independent research, testing, or tool development on security issues out of curiosity
  • Are active in industry groups (e.g., OWASP, DEF CON Groups, City-Sec Meetups, or other security meetups) and/or conferences (e.g., DEF CON, BlackHat, Summercon, THOTCON, WWHF, BSides, etc.)
  • Have utilized AI as a tool, but not a testing replacement, to improve coverage and efficiency
  • Located in Chicago-land area or open to relocation, but open to the right candidates across the US
  • You prefer the words “information security” or “computer security” over “cyber”

Qualifications

Must Haves

  • 4+ years of experience in penetration testing, either consulting or internal
  • Performed one or more of the following roles as a penetration tester: external network penetration testing, internal network penetration testing, wireless penetration testing, web application penetration testing, mobile application penetration testing, IOT device penetration testing, non-destructive physical security testing
  • Gained a strong technical knowledge and understanding of mixed-technology environments, include diverse operating systems, network hardware, web application languages, administration technologies, authentication mechanisms, and cloud platforms
  • Extensively used open source penetration testing tools and frameworks, such as (but not limited to) Metasploit, Burp, Nmap, etc
  • Developed or modified tools in scripting languages, such as Ruby, Python, GoLang, Perl, or Java, to assist in testing a problem
  • Learned the core fundamentals of computers, all the way down to protocol stacks
  • Paid enough attention in English class to write good (or is it well?) and know to self-QA deliverables before sending them to others
  • Creative, out-of-the-box thinker who can leverage various domains of knowledge to create uniquely tailored tests and solutions for complex problems
  • You're curious by nature, intrigued by how things work, and have an appetite to find weaknesses in their design and implementation
  • You prefer building, contributing, and leading over falling in line
  • You're happy to put in the extra effort building a tool that makes everyone's lives easier
  • Urbane team members value developing long-term client relationships over “drop the mic” moments. You want to provide remediation suggestions that address the core issues, are sustainable, and work within the confines of the target environment
  • You're passionate about technology and find entertainment in crazy personal projects (i.e., programming a USB Nerf gun and webcam to mess with your cat while you aren't at home, building an enterprise-grade virtualization environment in your bedroom closet, or seeing how many neighbors think your “free” wifi is actually “free”)
  • A desire to stay current with the latest technologies, attacks, and hardening strategies. You're a regular online reader of blogs and social media for the latest in security, enjoy good conference talks, and/or contribute to interesting projects
  • Driven personality, with a desire to continuously improve, put in the hours, and deliver. You take pride in your work, and you want it to be the best you can do
  • Not opposed to traveling and can survive occasions requiring Domestic/International travel (currently less than 25%, but subject to fluctuate)
  • Highly organized and detail-oriented with the ability to independently prioritize multiple projects while still balancing personal goals. You recognize when you need help, and aren't afraid to ask for it
  • Have a strong ethical compass and an understanding of ethics in business and information security. You'll respect scope limitations, clean up after your attacks, and never access or retain data that isn't pertinent to the testing
  • Equally comfortable holding your own with a technical audience (especially the Unix-Beards) as well as communicating to a non-technical audience (including the C-Suite), both in writing and verbally
  • Maintain a unique and independent identity, but respect other business' culture, including dress apparel, level of formality, and work schedules. We maintain a startup-style culture internally, while presenting a clean, elevated, and refined image to the rest of the world
  • Currently a US citizen or other permanent US resident

Nice to Haves

  • College or equivalent educational experience
  • Have fun acronyms after your name, such as OSCP, OSWP, GPEN, GWAPT, CPTE, CISSP, or are not opposed to getting them as needed
  • Experience in modifying or creating tools or payloads to exploit vulnerabilities not effectively covered in other exploitation frameworks
  • Have performed independent research, testing, or tool development on security issues out of curiosity
  • Are active in industry groups (e.g., OWASP, DEF CON Groups, City-Sec Meetups, or other security meetups) and/or conferences (e.g., DEF CON, BlackHat, Summercon, THOTCON, WWHF, BSides, etc.)
  • Have utilized AI as a tool, but not a testing replacement, to improve coverage and efficiency
  • Located in Chicago-land area or open to relocation, but open to the right candidates across the US
  • You prefer the words “information security” or “computer security” over “cyber”

Benefits

  • Standard benefit packages, including Medical/Dental/Vision, paid vacation time, 401k plan, and reimbursable internet/phone/gym plans.
  • Training and professional development stipends (yes, this includes conferences!).
  • Annual team meetings and occasional team events, including BlackHat / DEF CON week.
  • Exotic Travel Locations (like Arkansas!)
  • Captivating challenges, meaningful work, and ability to grow, both intellectually and within the company.

More jobs like this