Principal Penetration Testing Engineer
India - Hyderabad
Amgen
Amgen is committed to unlocking the potential of biology for patients suffering from serious illnesses by discovering, developing, manufacturing and delivering innovative human therapeutics.Career Category
Information SystemsJob Description
Join Amgen’s Mission of Serving Patients
At Amgen, if you feel like you’re part of something bigger, it’s because you are. Our shared mission—to serve patients living with serious illnesses—drives all that we do.
Since 1980, we’ve helped pioneer the world of biotech in our fight against the world’s toughest diseases. With our focus on four therapeutic areas –Oncology, Inflammation, General Medicine, and Rare Disease– we reach millions of patients each year. As a member of the Amgen team, you’ll help make a lasting impact on the lives of patients as we research, manufacture, and deliver innovative medicines to help people live longer, fuller happier lives.
Our award-winning culture is collaborative, innovative, and science based. If you have a passion for challenges and the opportunities that lay within them, you’ll thrive as part of the Amgen team. Join us and transform the lives of patients while transforming your career.
Principal Penetration Testing Engineer
What you will do
Let’s do this. Let’s change the world. In this vital role has a strong focus on ensuring the organization's infrastructure, applications, and systems are secure from external and internal threats. As a senior-level position, this role involves not only hands-on penetration testing but also overseeing teams, setting testing strategies, and working closely with other security and engineering teams to implement long-term security improvements. The ideal candidate has in-depth knowledge of cybersecurity practices, experience in complex security assessment practices and strong leadership skills.[BB1] [MG2]
Roles & Responsibilities:
Ø Perform advanced security testing (e.g., penetration testing, code reviews) and ensure continuous security monitoring across the organization’s IT landscape.
Ø Identify vulnerabilities in networks, systems, applications, and infrastructure through hands-on penetration testing.
Ø Attempt to exploit discovered vulnerabilities to demonstrate their impact and prove their existence (e.g., retrieving sensitive data, elevating user privileges, or gaining access to admin functionality).
Ø Perform assessments on web applications, cloud environments, and network infrastructure.
Ø Use automated tools and manual techniques to identify security weaknesses.
Ø Conduct advanced post-exploitation tasks to simulate real-world attack scenarios.
Ø Build or modify existing penetration testing tools to streamline testing processes.
Ø Implement automation frameworks to improve the efficiency and repeatability of vulnerability assessments and penetration tests.
Ø Guide junior penetration testers in techniques, toolsets, and reporting.
Ø Assist in developing the skills of the cybersecurity team through formal and informal training sessions.
Ø Review and ensure the quality of penetration testing reports and findings of junior testers.
Ø Work with third-party security vendors for audits, product testing, and external assessments when required.
Ø Use automated tools (e.g., Burp Suite, OWASP ZAP, or Acunetix) to identify common vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and others.
Ø Document identified vulnerabilities in detail, explaining how they were found, their severity, and their potential impact. Include proof-of-concept (PoC) for critical vulnerabilities.
Ø Offer actionable, practical solutions for fixing vulnerabilities, such as secure coding practices, configuration changes, or security controls.
Ø Use risk-based prioritization, categorizing issues by their severity and business impact (e.g., high, medium, low) to help the organization focus on the most critical issues.
Ø Continuously learn about the latest vulnerabilities, exploits, and security trends.
Ø Present the findings to stakeholders, security teams, and management, explaining the business risk and potential impacts of the vulnerabilities discovered.
Ø Provide broader application security recommendations, such as adopting secure development frameworks, improving logging and monitoring, or enhancing incident response capabilities.
Ø Provide guidance and feedback on the organization's security policies and incident response plans based on findings from penetration tests.
Ø Serve as a trusted advisor on key security decisions and risk management.[BB3] [MG4]
Familiarity with industry standards and compliance requirements (e.g., PCI-DSS, NIST, ISO 27001) and their relevance to penetration testing.
Since the role will be technical, I recommend downplaying (not removing) strong leadership skills. [BB1]
No disconfirm. Accept edit. [MG2]
Same as before, downplaying business facing interaction to focus on technical expertise. We can handle interaction with senior leadership. [BB3]
No disconfirm. Accept edit. [MG4]
What we expect of you
We are all different, yet we all use our unique contributions to serve patients.
Master’s degree and 8 to 10 year of experience in Computer Science, Cybersecurity or Information Systems related field OR
Bachelor’s degree and 10 to 14 year of experience in Computer Science, Cybersecurity or Information Systems related field OR
Diploma and 14 to 18 year of experience in Computer Science, Cybersecurity or Information Systems related field
Must-Have Skills:
Strong knowledge of common vulnerabilities (e.g., OWASP Top 10, SANS Top 25), network protocols, encryption standards, application security and common penetration testing methodologies (ISSAF, OSSTMM, PTES).
Familiarity with tools like Burp Suite, OWASP ZAP and Metasploit.
A deep understanding of web application architecture, databases, and authentication mechanisms.
Ability to think critically and creatively when testing and attempting to exploit vulnerabilities.
Preferred Qualifications:
Good-to-Have Skills:
Experience with threat intelligence and incorporating emerging threats into penetration testing practices
Proficiency in scripting and automation (e.g., Python, Bash) is a plus
Professional Certifications (please mention if the certification is preferred or mandatory for the role):
Preferred: OSCP, OSWE, OSWA, eWPTX, GWAPT, GXPN
Preferred: CISSP
Soft Skills:
Excellent analytical and troubleshooting skills
Strong verbal and written communication skills
Ability to work effectively with global, virtual teams
High degree of initiative and self-motivation
Ability to manage multiple priorities successfully
Team oriented, with a focus on achieving team goals
Strong presentation and public speaking skills
What you can expect of us
As we work to develop treatments that take care of others, we also work to care for your professional and personal growth and well-being. From our competitive benefits to our collaborative culture, we’ll support your journey every step of the way.
In addition to the base salary, Amgen offers competitive and comprehensive Total Rewards Plans that are aligned with local industry standards.
Apply now
for a career that defies imagination
Objects in your future are closer than they appear. Join us.
careers.amgen.com
As an organization dedicated to improving the quality of life for people around the world, Amgen fosters an inclusive environment of diverse, ethical, committed and highly accomplished people who respect each other and live the Amgen values to continue advancing science to serve patients. Together, we compete in the fight against serious disease.
Amgen is an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other basis protected by applicable law.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
.* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Audits Automation Bash Burp Suite CISSP Cloud Compliance Computer Science CSRF Encryption eWPTx Exploit Exploits GWAPT GXPN Incident response ISO 27001 Metasploit Monitoring NIST OSCP OSWE OWASP Pentesting Python Risk management SANS Scripting Security assessment SQL SQL injection Threat intelligence Vulnerabilities XSS
Perks/benefits: Career development Competitive pay
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.