368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$97k – $194k per year (Estimated)
Location
In office (Philadelphia)
Seniority
Senior · 2+ years exp
Overview
Company
Impact
Profile match
Wij bieden in de Benelux een scala aan verzekeringsproducten voor particulieren, families en bedrijven. Wij hebben onder andere verzekeringsproducten op het gebied van Ongevallen & Welzijn, Financial Lines, Transport, Brand- en Bedrijfsschade, Aansprakelijkheid, Reizen en Overlijdensrisico.
  • Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications
  • Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
  • Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls
  • Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications
  • Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
  • Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters
  • Manage application risk rating processes and ensure timely risk scoring of new and changing applications
  • Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines
  • Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders
  • Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program

Minimum:

  • Prior experience managing Information Security projects
  • Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline, or equivalent relevant experience
  • Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing
  • Knowledge of prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets
  • Knowledge of industry standards regarding vulnerability management, including Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS)
  • Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening and security baselines, and web server and database security
  • Knowledge of penetration testing principles, tools, and techniques
  • Working experience with industry frameworks (OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, NIST, NIST AI Risk Management Framework, MITRE ATT&CK, etc.)
  • Comfortable working outside their comfort zone with a willingness to learn
  • Excellent verbal and written communication skills
  • Strong analytical skills
  • Strong team player with the ability to work independently
  • Strong project management skills and ability to multi-task
  • Self-motivated with strong initiative
  • Knowledge of computer networking concepts and protocols, and application security methodologies
  • Skill in performing impact/risk assessments
  • Familiarity with modern application architectures, including cloud-native (AWS, Azure, GCP), containerized (Docker, Kubernetes), microservices, and API-first (REST, GraphQL, gRPC) designs
  • Foundational understanding of AI/ML and generative AI security risks (e.g., prompt injection, model manipulation, sensitive data leakage) is a plus

Nice To Have:

  • Strong understanding of secure SDLC, exploit/attack techniques, and core networking, application, and OS concepts, with the ability to manipulate application logic, bypass security controls, and develop exploits
  • Experience scoping and leading engagements end-to-end - from kickoff through remediation tracking - and improving testing efficiency through automation, tooling, and process improvements
  • Proficient with industry-standard tools across categories: Kali Linux, Metasploit, Nmap, Burp Suite/OWASP ZAP (web); Santoku, Genymotion, APKTool, JD-GUI (mobile); SQLMap, Semgrep, Snyk, Checkmarx/AppScan/Veracode (code); Postman/Insomnia (API); Trivy/Grype, Prowler/ScoutSuite (cloud & containers); and Garak/PyRIT (AI red-teaming)
  • Skilled in identifying OWASP Top 10 (Web & Mobile), OWASP API Security Top 10, and OWASP LLM Top 10 vulnerabilities, and developing secure coding checklists based on OWASP ASVS
  • Experience conducting full-scope assessments and penetration tests - web, mobile, API, social engineering, and server/client-side attacks - including mobile reverse engineering (hardcoded credentials, SQLi, keychain exposure, anti-emulator/obfuscation bypass)
  • Experience assessing cloud-native and containerized applications (AWS, Azure, GCP, Docker, Kubernetes), modern CI/CD pipelines and Infrastructure as Code, and modern API architectures (REST, GraphQL, gRPC) including OAuth2/OIDC/JWT flaws
  • Experience or working knowledge testing AI/ML and generative AI features for risks such as prompt injection, insecure output handling, training data poisoning, and sensitive data disclosure, aligned to the OWASP LLM Top 10 and MITRE ATLAS, plus working knowledge of securing AI agent/orchestration frameworks (LangChain, Semantic Kernel, AutoGen) and RAG vector databases
  • Skilled in code analysis, exploit development, and using attacker tools/tactics/procedures to identify, validate, and demonstrate vulnerabilities an adversary could exploit
  • Ability to analyze findings (including root cause analysis), risk-rate vulnerabilities by actual business impact, and prioritize key risk areas
  • Ability to document findings clearly, including reproduction steps, and produce comprehensive, accurate penetration test reports
  • Ability to research and recommend practical short- and long-term remediations, and communicate findings and strategy effectively to both technical and executive stakeholders
  • Experience working closely with development teams to track remediation through to production deployment, maintain vulnerability status dashboards, and follow up on overdue items to meet compliance timelines
  • Preferred certifications: OSCP, OSWE, GWAPT, GPEN, CEH, GCPN, CCSP, or equivalent AI/ML security credentials
  • Strong communicator and collaborative team player, able to adapt and reprioritize as project needs shift
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Philadelphia
$70k – $150k per year • In office • Full-Time • 5+ years exp • Calgary
Java
Node JS
Python
SQL
TypeScript
JavaScript
Java
Spring Boot
Databases
Apache Kafka
Chroma
OpenSearch
pgvector
Pinecone
PostgreSQL
AI/ML
AWS Bedrock
Copilot
Embeddings
LangChain
LangGraph
LLM
Prompt Engineering
RAG
AI Agents
Anthropic
Function Calling
Human-in-the-Loop
OpenAI
Structured Outputs
Frontend
Angular
React.js
DevOps
AWS
Azure
CI/CD
Docker
Kubernetes
Vector
Apply
$105k – $175k per year • In office • Full-Time • Raleigh
Python
AI/ML
AI Agents
Amazon SageMaker
AutoGen
AWS Bedrock
CrewAI
Edge AI
Function Calling
LangChain
LangGraph
Model Context Protocol
NLP
Prompt Engineering
PyTorch
RAG
TensorFlow
DevOps
Amazon EC2
Amazon ECS
Amazon EKS
Amazon S3
AWS
AWS Lambda
Azure
GCP
Git
Kubernetes
Apply
$59k – $99k per year • In office • Full-Time • Bachelor's Degree • Boca Raton
C++
JavaScript
Python
SQL
C#
C#
.NET
DevOps
AWS
Azure
Apply
$59k – $99k per year • In office • Full-Time • Bachelor's Degree • Alpharetta
C++
JavaScript
Python
SQL
C#
C#
.NET
DevOps
AWS
Azure
Apply
$44k – $58k per year • Remote/Hybrid • Full-Time • 2+ years exp • Associate's Degree • Vancouver
Bash
Python
SQL
Databases
MS SQL
MySQL
Oracle
PostgreSQL
DevOps
AWS
Azure
GCP
VMWare
Windows Server
Apply
In office • 3+ years exp • Bachelor's Degree
Python
SQL
AI/ML
AI Agents
Anomaly Detection
Copilot
DevOps
AWS
Git
Analytics
Power BI
Tableau
Apply
In office • 7+ years exp • Bachelor's Degree
JavaScript
SQL
TypeScript
DevOps
CI/CD
QA
Playwright
Selenium
Apply
$174k – $200k per year • In office • 5+ years exp • Bachelor's Degree • Jersey City
JavaScript
Design
Figma
Apply
Senior Data Analyst 4 days ago
Equity • Remote/Hybrid • 7+ years exp • Bachelor's Degree
PowerShell
Python
SQL
Databases
Azure SQL Database
MS SQL
PostgreSQL
Snowflake
AI/ML
dbt
DevOps
Azure
Git
Platform Engineering
SLI/SLO/SLA
Cybersecurity
GDPR
Analytics
Power BI
ETL/ELT
Apply
$57k – $116k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Philadelphia
AI/ML
Model Context Protocol
Apply
$64k – $134k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Philadelphia
PowerShell
DevOps
Red Hat
VMWare
Windows Server
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
Junior Cloud Engineer 9 hours ago
$70k – $75k per year • In office • Full-Time • Philadelphia
Python
SQL
DevOps
AWS
IAM
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.