Penetration Test Engineer (Remote)

Sorry, this job was removed at 5:22 a.m. (CST) on Saturday, February 6, 2021
Find out who's hiring in Austin.
See all Developer + Engineer jobs in Austin
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

About the Role:

Good at breaking things? Have a strong passion for security best practices? This job is for you! This position is responsible for developmental and operational penetration testing for CrowdStrike assets, infrastructure and online properties.

This position requires someone with expertise in manual and automated web application penetration testing with the knowledge needed to breach security defenses. The ideal candidate will have at least two years of experience performing penetration tests using a mix of commercially available, open source and personally built tools. A solid understanding of network protocols, server and web application weaknesses is also needed.

The successful candidate will have strong communication skills and poses the ability to speak to all levels while working in a complex distributed cloud-based environment.

Additional Responsibilities:

  • Perform comprehensive penetration testing assessments across the organization.

  • Manage the entire lifecycle of penetration testing findings from discovery, triage, advising, remediation, and validation.

  • Work with various different business units to perform penetration testing assessments on systems, infrastructure and applications before go live rollouts.

  • Work with third-party vendors to ensure they are meeting and adhering to the organization’s security requirements.

  • Examine public facing and internal web applications to discover security weaknesses which present undue security risk to the organization.

  • Examine systems and applications to assess the current security posture.

  • Manage penetration testing related tickets to drive remediation and ensure issues are on track to be completed within proper timelines.

  • Advocate for security best practices across the organization.

What You’ll Need:

  • Advanced knowledge of server and client operating systems.

  • Advanced knowledge of web application security issues and poses capabilities to assess common weaknesses including, but not limited to those within OWASP top 10.

  • Extensive computer skills and an understanding of networking, cryptography, web applications, databases, virtualization, containers, and wireless technologies.

  • Deep understanding of dynamic cloud environments and common security weaknesses related to the cloud.

  • Ability to prioritize impactful findings and drive items to remediation.

  • Experience working with Mac, Windows, Linux and/or other Unix-like variants.

  • Extensive understanding of TCP, UDP, HTTP, IP and other network protocols.

  • A detailed understanding of how to triage vulnerabilities using CVSS calculators and the ability to validate security related findings.

  • Possess the ability to work independently.

  • Proactive go getter attitude to solve challenging problems.

  • Stays up to date with current vulnerabilities and new attack techniques.

  • Ability to automate and script tasks using your preferred language (e.g. Golang, Python, Ruby, Rust, C, C++, BASH, etc.)

  • The ability to work with teammates across the organization in different time zones and maintain healthy working relationships.

  • Technical security certifications or academic background a plus.

  • CVEs or bug bounty rewards

  • Documented CTF writeups or victories

  • Professional group affiliations

  • Open Source project contributions

Bonus Points:

  • Experience conducting web application and web API penetration testing.

  • Experience working with bug bounty programs.

  • Experience executing effective email phishing campaigns with custom domains, website hosting, payload delivery, credential harvesting, antivirus bypass techniques, and additional components within this area.

  • Ability to utilize and write scripts against common web APIs (REST, SOAP).

  • Knowledge of cloud platforms and highly concurrent systems.

  • Knowledge of build pipelines and CI tools.

  • You’re a clear thinker and efficient communicator (i.e. written and verbal).

  • Ability to create elegant looking PowerPoints or Slide Decks.

#LI-LY1

#LI-LAC1

#LI-Remote

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Sales & Marketing
    • GolangLanguages
    • PythonLanguages
    • KafkaFrameworks
    • KubernetesFrameworks
    • CassandraDatabases
    • ElasticsearchDatabases
    • RedisDatabases
    • AWS (Amazon Web Services)Services
    • SalesforceCRM

Location

Fantastic downtown location walking distance to awesome restaurants and happy hour spots.

An Insider's view of CrowdStrike

How does your team reward individual success?

One way we reward sales reps is with opportunities to grow their skills and prep for their next role. Whether that’s extra shadowing sessions or running calls, we encourage our high performers to explore new avenues that align with their future goals.

Kristan C.

Sr. Manager, Sales Development

What kinds of technical challenges do you and your team face?

Working with a high volume of new customers offers a lot of opportunities to appreciate the diversity of the technical ecosystem. We work with one-person teams to full C-suites and everything in between. As a team, our greatest challenge and our greatest strength is variety.

Bradley Q.

Regional Sales Engineer

How does the company support your career growth?

CrowdStrike thrives on developing and promoting our people. There are multiple programs in place for those interested in leadership, and employees are encouraged to have peer conversations about roles they are interested in. These resources really help people like me accelerate our career growth.

Marit M.

Manager, Corporate Renewals

How do you make yourself accessible to the rest of the team?

With a global team, it’s crucial to be intentional in how and when we meet. I prioritize scheduling regular skip level meetings with my individual contributors and protect 1:1 manager meetings so I can be present and engaged. I always try my best to ensure the team feels well supported, no matter how busy we get

Alyssa J.

Senior Director, Global Customer Sales

What does career growth look like on your team?

Every year, I have a goal to promote at least 1-2 people on my team. When I sit down with an individual on my team, we lay out what their personal and professional goals are for the year and beyond and outline the major steps we can take to help them reach those goals. It’s very satisfying to watch your teammates grow personally and professionally.

Vince L.

Manager, Corporate Sales

What are CrowdStrike Perks + Benefits

CrowdStrike Benefits Overview

We offer flexible schedules and the ability to “work from anywhere,” a comprehensive benefits package, health and wellness programs, fully stocked company pantry, company and team events, and commuter benefits. We have an official mentorship program and many other professional development programs available to all employees. We offer free webinars on everything from financial wellness and mental health to sessions with coaching experts and speakers on topics related to diversity, equity & inclusion. We also offer our people the chance to work on passion projects and innovation during our annual “Think Week” as well as peer recognition and reward programs like Team Bravo award for cross-functional collaboration and Hero award for those who embody our core values and live our culture.

Culture
Volunteer in local community
CrowdStrike supports employees in charitable efforts and community service for charities and causes important to the local team.
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity employee resource groups
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Mental health benefits
Financial & Retirement
401(K)
Competitive 401(k) plan.
401(K) matching
Company equity
RSU's are available as part of employee compensation.
Employee stock purchase plan
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Generous parental leave
CrowdStrike provides 12 weeks of parental leave for the primary caregiver and 8 weeks leave for the secondary care giver.
Family medical leave
Adoption Assistance
Return-to-work program post parental leave
Company sponsored family events
We sponsor company-wide bring your child to work days as well as company events where family is encouraged to attend.
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid volunteer time
Paid holidays
Paid sick days
Office Perks
Commuter benefits
We offer pre-tax commuter benefits.
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Relocation assistance
Professional Development
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education available during work hours
Online course subscriptions available

More Jobs at CrowdStrike

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about CrowdStrikeFind similar jobs like this