Principal Penetration Testing Engineer

India - Hyderabad

Amgen

Amgen is committed to unlocking the potential of biology for patients suffering from serious illnesses by discovering, developing, manufacturing and delivering innovative human therapeutics.

View all jobs at Amgen

Apply now Apply later

Career Category

Information Systems

Job Description

Join Amgen’s Mission of Serving Patients

At Amgen, if you feel like you’re part of something bigger, it’s because you are. Our shared mission—to serve patients living with serious illnesses—drives all that we do.

Since 1980, we’ve helped pioneer the world of biotech in our fight against the world’s toughest diseases. With our focus on four therapeutic areas –Oncology, Inflammation, General Medicine, and Rare Disease– we reach millions of patients each year. As a member of the Amgen team, you’ll help make a lasting impact on the lives of patients as we research, manufacture, and deliver innovative medicines to help people live longer, fuller happier lives.

Our award-winning culture is collaborative, innovative, and science based. If you have a passion for challenges and the opportunities that lay within them, you’ll thrive as part of the Amgen team. Join us and transform the lives of patients while transforming your career.

Principal Penetration Testing Engineer

What you will do

Let’s do this. Let’s change the world. In this vital role has a strong focus on ensuring the organization's infrastructure, applications, and systems are secure from external and internal threats. As a senior-level position, this role involves not only hands-on penetration testing but also overseeing teams, setting testing strategies, and working closely with other security and engineering teams to implement long-term security improvements. The ideal candidate has in-depth knowledge of cybersecurity practices, experience in complex security assessment practices and strong leadership skills.[BB1] [MG2]

Roles & Responsibilities:

Ø Perform advanced security testing (e.g., penetration testing, code reviews) and ensure continuous security monitoring across the organization’s IT landscape.

Ø Identify vulnerabilities in networks, systems, applications, and infrastructure through hands-on penetration testing.

Ø Attempt to exploit discovered vulnerabilities to demonstrate their impact and prove their existence (e.g., retrieving sensitive data, elevating user privileges, or gaining access to admin functionality).

Ø Perform assessments on web applications, cloud environments, and network infrastructure.

Ø Use automated tools and manual techniques to identify security weaknesses.

Ø Conduct advanced post-exploitation tasks to simulate real-world attack scenarios.

Ø Build or modify existing penetration testing tools to streamline testing processes.

Ø Implement automation frameworks to improve the efficiency and repeatability of vulnerability assessments and penetration tests.

Ø Guide junior penetration testers in techniques, toolsets, and reporting.

Ø Assist in developing the skills of the cybersecurity team through formal and informal training sessions.

Ø Review and ensure the quality of penetration testing reports and findings of junior testers.

Ø Work with third-party security vendors for audits, product testing, and external assessments when required.

Ø Use automated tools (e.g., Burp Suite, OWASP ZAP, or Acunetix) to identify common vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and others.

Ø Document identified vulnerabilities in detail, explaining how they were found, their severity, and their potential impact. Include proof-of-concept (PoC) for critical vulnerabilities.

Ø Offer actionable, practical solutions for fixing vulnerabilities, such as secure coding practices, configuration changes, or security controls.

Ø Use risk-based prioritization, categorizing issues by their severity and business impact (e.g., high, medium, low) to help the organization focus on the most critical issues.

Ø Continuously learn about the latest vulnerabilities, exploits, and security trends.

Ø Present the findings to stakeholders, security teams, and management, explaining the business risk and potential impacts of the vulnerabilities discovered.

Ø Provide broader application security recommendations, such as adopting secure development frameworks, improving logging and monitoring, or enhancing incident response capabilities.

Ø Provide guidance and feedback on the organization's security policies and incident response plans based on findings from penetration tests.

Ø Serve as a trusted advisor on key security decisions and risk management.[BB3] [MG4]

Familiarity with industry standards and compliance requirements (e.g., PCI-DSS, NIST, ISO 27001) and their relevance to penetration testing.

Since the role will be technical, I recommend downplaying (not removing) strong leadership skills. [BB1]

No disconfirm. Accept edit. [MG2]

Same as before, downplaying business facing interaction to focus on technical expertise. We can handle interaction with senior leadership. [BB3]

No disconfirm. Accept edit. [MG4]

What we expect of you

We are all different, yet we all use our unique contributions to serve patients.

Master’s degree and 8 to 10 year of experience in Computer Science, Cybersecurity or Information Systems related field OR

Bachelor’s degree and 10 to 14 year of experience in Computer Science, Cybersecurity or Information Systems related field OR

Diploma and 14 to 18 year of experience in Computer Science, Cybersecurity or Information Systems related field

Must-Have Skills:

  • Strong knowledge of common vulnerabilities (e.g., OWASP Top 10, SANS Top 25), network protocols, encryption standards, application security and common penetration testing methodologies (ISSAF, OSSTMM, PTES).

  • Familiarity with tools like Burp Suite, OWASP ZAP and Metasploit.

  • A deep understanding of web application architecture, databases, and authentication mechanisms.

  • Ability to think critically and creatively when testing and attempting to exploit vulnerabilities.

Preferred Qualifications:

Good-to-Have Skills:

  • Experience with threat intelligence and incorporating emerging threats into penetration testing practices

  • Proficiency in scripting and automation (e.g., Python, Bash) is a plus

Professional Certifications (please mention if the certification is preferred or mandatory for the role):

  • Preferred: OSCP, OSWE, OSWA, eWPTX, GWAPT, GXPN

  • Preferred: CISSP

Soft Skills:

  • Excellent analytical and troubleshooting skills

  • Strong verbal and written communication skills

  • Ability to work effectively with global, virtual teams

  • High degree of initiative and self-motivation

  • Ability to manage multiple priorities successfully

  • Team oriented, with a focus on achieving team goals

  • Strong presentation and public speaking skills

What you can expect of us

As we work to develop treatments that take care of others, we also work to care for your professional and personal growth and well-being. From our competitive benefits to our collaborative culture, we’ll support your journey every step of the way.

In addition to the base salary, Amgen offers competitive and comprehensive Total Rewards Plans that are aligned with local industry standards.

Apply now

for a career that defies imagination

Objects in your future are closer than they appear. Join us.

careers.amgen.com

As an organization dedicated to improving the quality of life for people around the world, Amgen fosters an inclusive environment of diverse, ethical, committed and highly accomplished people who respect each other and live the Amgen values to continue advancing science to serve patients. Together, we compete in the fight against serious disease.

Amgen is an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other basis protected by applicable law.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

.
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Application security Audits Automation Bash Burp Suite CISSP Cloud Compliance Computer Science CSRF Encryption eWPTx Exploit Exploits GWAPT GXPN Incident response ISO 27001 Metasploit Monitoring NIST OSCP OSWE OWASP Pentesting Python Risk management SANS Scripting Security assessment SQL SQL injection Threat intelligence Vulnerabilities XSS

Perks/benefits: Career development Competitive pay

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.