Penetration Tester - Intermediate Level
San Antonio Home Office I, United States
USAA
USAA offers competitive auto rates, no-monthly service fee banking and retirement options to all branches of the military and their family. Join now and let us serve you.Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
The Opportunity
As a dedicated Penetration Tester - Intermediate Level, you will work with the Application and Infrastructure Security team that performs penetration testing to evaluate the security posture of USAA developed applications and USAA infrastructure. The goal of the assessment is to evaluate the USAA assets' resilience to common security threats and confirm the efficacy of the implemented security defense mechanisms.
Within defined guidelines and framework, investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA’s environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate collaborators. Stays current with the latest information security threats, exploits, trends, and intelligence.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Or Charlotte, NC. Relocation assistance is not available for this position.
What you'll do:
Maintains awareness of the latest critical information security vulnerabilities, threats, and exploits.
Assists in conducting routine vulnerability management, security configuration assessments, and/or penetration testing operations.
Monitors internal and external networks, systems, and applications for security anomalies and events (e.g. suspicious behavior, attacks, and security breaches).
Assists in responding to cyber incidents, performing moderately complex analysis using security tools. Builds a broad range of knowledge, understanding, and experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures.
Under direct supervision, uses the discoveries from the incident response process to make basic improvements to the existing detection capabilities and security controls.
Documents findings of completed alerts and assists with incident documentation.
Serves as a resource to team members on raised issues of a routine nature.
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
2 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for moderately complex tasks and/or projects.
1 year of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
Developing level of business insight in the areas of business operations, risk management, industry practices and emerging trends.
What sets you apart:
Hold any of the following certifications: Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), Penetration Testing + (Pentest+), Licensed Penetration Tester (LPT), GIAC Web Application Penetration Tester (GWAPT).
2 years’ experience in developing, documenting, and administrating the penetration testing lifecycle.
2 years’ experience crafting detailed reports and findings.
Experience configuring and using Windows and Linux/Unix operating systems.
Compensation range: The salary range for this position is: $77,120.00 - $147,390.00.
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Tags: Compliance Cyber defense Exploits Forensics GIAC GPEN GWAPT IAM Incident response Linux Network security Offensive security OSCP Pentesting Risk management Security assessment UNIX Vulnerabilities Vulnerability management Windows
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Insurance Relocation support Team events Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.