Penetration Tester 3

United States

Oracle

Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.

View all jobs at Oracle

Apply now Apply later

As part of Oracle Customer Success Services, Risk Management & Security Services organization's mission is to increase Oracle’s value potential in the security services market by providing a managed security and compliance center of excellence that draws together the existing Oracle Tooling, Cloud Services and Oracle Professional Services to build a holistic thoughtful Security and Compliance Offering tailored to the customers' needs in the Hybrid cloud environment. We manage security across a vast array of customer environments- small business, global enterprise, government, and everything in between.

We are looking for experienced penetration testers with the enthusiasm and maturity to develop themselves further and join us in pushing our global team’s capabilities to a new level. A track record of self-education and an ability to adapt comfortably to change is necessary, and we'll do our part by providing regular formal training to keep your skills and certifications up to date.

Sharing knowledge and working eagerly with a team is key to success here, and you will lead our pentesting platforms, tooling and evolving comprehensive methodologies. This is an exciting chance to bring your skills to a global Cloud program!

A Glimpse At Our Toolkit:

Information Gathering & Scanning Phase: we use a variety of tools including: Nmap, Socat, Burpsuite Pro, Nessus, Qualys, WebInspect, Paros, CryTool, HTTPLiveHeaders, sqlmap and others to map assets and services in the larger environment.

Penetration Testing Phase: You'll devise and execute the pen test attack plan using human engineered, multiple exploits (Eg. missing patches and service mis-configurations, recognized attack vectors, etc). Tools we may use include: Webscarab Proxy, Medusa, Hydra, CrowBar, Metasploit, publicly available exploit code, proprietary and self-authored tools, and manual testing.

Reporting & Remediation: You'll be responsible for concluding your findings with a report to the Security Manager. This will be leveraged with the customer and other Oracle teams for remediation recommendations.

What the Penetration Tester/Pentester/Ethical Hacker will do:
   • Conduct network and server layer penetration testing against Oracle Cloud customers and internal systems
   • Conduct application-layer penetration testing against Oracle Cloud customers’ software applications and webservices deployed globally
   • Conduct penetration testing of new Oracle solutions deployed internally to support Oracle customers as part of  the Corporate Security Solution Assurance Process.
   • Conduct rigorous penetration testing of Oracle’s latest generation Cloud Services  (SaaS, PaaS, IaaS)
   • Document technical issues identified during security assessments, and author formal customer-facing reports
   • Follow up on implementation of corrective actions from assessments
   • Research security threats and attack vectors
   • Develop novel tooling and techniques to enhance the team’s platform and capabilities
   • Perform special security projects on an ad-hoc basis

What we want to see in the Penetration Tester/Pentester/Ethical Hacker:
• Established professional or military experience with Penetration testing/ethical hacking (3+ years preferred)
• Curiosity about learning anything that has to do with discovering vulnerabilities and exploiting them
• Professional certification: CEH, OSCP, OSCE/ OSWE or equivalent
• Solid education in Information Security and technical aspects thereof, CISSP certification preferred
• Hands-on experience with systems development, systems administration, or network administration, 2-5+ years ideal
• Hands-on experience in automated and manual penetration testing (infrastructure and web app/ service), 2-5+ years ideal
• Knowledge of Information Security standards and access controls such as ISO27001/2 and PCI DSS
• Good interpersonal skills and diligent, able to handle concurrent assignments
• Self-starter and self-sufficient, doesn’t need to be micro-managed

What will make you stand out:
• Self-educated, self-starters do well in this team, where passion and individual pursuits will be complemented by training and mentorship
• Personable, open, and collaborative approach coupled with precise independent execution skills and creativity
• Professional or extensive hobby experience with x86/x64 assembly, Java, Python, Ruby, Lua, or Go
• Professional experience building web applications, software, or systems engineering
• Knowledge of container platforms including Docker and Kubernetes
• CEH, OCSP, GPEN, GXPN, or other related certifications
• Understanding of reverse engineering, malware, debuggers, kernel memory layout in Windows and Linux
• Scripting/ programming experience (BASH, PowerShell, Python, C, Assembler) is an advantage
 

Career Level - IC3

   • Conduct network and server layer penetration testing against Oracle Cloud customers and internal systems
   • Conduct application-layer penetration testing against Oracle Cloud customers’ software applications and webservices deployed globally
   • Conduct penetration testing of new Oracle solutions deployed internally to support Oracle customers as part of  the Corporate Security Solution Assurance Process.
   • Conduct rigorous penetration testing of Oracle’s latest generation Cloud Services  (SaaS, PaaS, IaaS)
   • Document technical issues identified during security assessments, and author formal customer-facing reports
   • Follow up on implementation of corrective actions from assessments
   • Research security threats and attack vectors
   • Develop novel tooling and techniques to enhance the team’s platform and capabilities
   • Perform special security projects on an ad-hoc basis

Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $87,000 to $178,100 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s problems. True innovation starts with diverse perspectives and various abilities and backgrounds.

When everyone’s voice is heard, we’re inspired to go beyond what’s been done before. It’s why we’re committed to expanding our inclusive workforce that promotes diverse insights and perspectives.

We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer a highly competitive suite of employee benefits designed on the principles of parity and consistency. We put our people first with flexible medical, life insurance and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by calling +1 888 404 2494, option one.

Disclaimer:

Oracle is an Equal Employment Opportunity Employer*. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

* Which includes being a United States Affirmative Action Employer

Apply now Apply later
Job stats:  1  0  0
Category: PenTesting Jobs

Tags: Bash Burp Suite C CEH CISSP Cloud Compliance Docker Ethical hacking Exploit Exploits GPEN GXPN IaaS ISO 27001 Java Kubernetes Linux Lua Malware Metasploit Nessus Nmap Oracle OSCE OSCP OSWE PaaS PCI DSS Pentesting PowerShell Python Qualys Reverse engineering Risk management Ruby SaaS Scripting Security assessment Vulnerabilities Windows

Perks/benefits: 401(k) matching Career development Competitive pay Equity / stock options Flex hours Flexible spending account Flex vacation Health care Insurance Medical leave Parental leave Salary bonus

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.