Full-Time

Lead Penetration Tester

Confirmed live in the last 24 hours

Blue Yonder

Blue Yonder

1,001-5,000 employees

Data & Analytics
Automotive & Transportation
Industrial & Manufacturing
Enterprise Software
Consumer Goods

Compensation Overview

$120.3k - $151.7kAnnually

+ Annual Performance Bonus + Commission Program

Senior, Expert

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
AWS
Requirements
  • 10+ years of Penetration Testing, Ethical Hacking and/or Red Teaming experience.
  • Must have worked with products/tools such as Qualys, Tenable, Nexpose, Metasploit, Core Impact, Burp Suite, Cobalt Strike, etc.
  • Certifications such as OSCP, OSCE, CRTP and/or GPEN.
  • TTP (Tactics, Techniques and Procedures) such as Mitre Framework.
  • Bachelor’s degree in information security, MIS, or Computer Science highly preferred.
Responsibilities
  • Create and maintain a solid penetration testing program for the organization, a key role within security organization
  • Conduct all the penetration activities for the Blue Yonder infrastructure
  • Co-ordinate customer requests for penetration testing
  • Focus on all the phases of penetration testing including, Information gathering, scanning, execution, post-exploitation, custom/meaningful reporting, remediation activities
  • Out of several thousand assets, identify the assets that need prioritization to be assessed
  • Potential to expand to a Red team with a focus on validating the security controls and security tools that are in place
  • This candidate would ultimately create awareness about the extent of compromise one could make with the current security posture – so that the asset owners can truly understand the security posture of their products and their network
  • Creates processes for the penetration testing program considering all the phases of the program
  • Leverage vulnerability scan results from all the scanners
  • Leverage threat intelligence information to raise the bar on Pen Testing program
  • Evaluate threats, vulnerabilities and risk in cloud platforms like Azure, AWS, etc.
  • Be responsible for not only identification of results but to provide solid feedback to the stake holders and to reduce the risk exposure
  • Capable of validating security controls that are in place with the organization like intrusion prevention systems and intrusion detection systems, etc.
  • An expert in post exploitation to truly determine the extent of compromise, upon identifying vulnerabilities
  • Describe the root cause and impacts to the asset owners
  • Demonstrate the risk through verbal and video demonstration in layman terms as needed
  • Reduce the open vulnerabilities by providing remediation guidance and feedback as needed
  • Document and track all the hacking activities for Management and auditors
  • Represent the team for internal and external auditors as needed
  • Review reports for each assessment before it is sent to the asset owners or to the customers
  • Participate in and assist with incident response team, as appropriate.
  • Generate metrics for the Management as needed.
  • Prepare system security reports by collecting, analyzing, and summarizing data and trends
  • Any other security related duties assigned by the Management.

Company Stage

Acquired

Total Funding

$73M

Headquarters

Scottsdale, Arizona

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • The significant investment in acquisitions, totaling nearly $1 billion since Q4 2023, indicates Blue Yonder's commitment to expanding its capabilities and market reach, potentially leading to increased job opportunities and career growth.

What critics are saying

  • The integration of One Network Enterprises could present challenges in aligning technologies and cultures, which may impact operational efficiency and employee satisfaction.

What makes Blue Yonder unique

  • Blue Yonder's acquisition of One Network Enterprises for $839 million positions it as a leader in creating a multi-enterprise supply chain ecosystem, setting it apart from competitors who may not offer such comprehensive solutions.

Help us improve and share your feedback! Did you find this helpful?