🌍 Global Remote Network: Over 120,085+ verified remote jobs with transparent salaries & visa sponsorship. Browse Remote Jobs →
S

Penetration Tester

πŸ“ Mountain View, CA πŸ•’
Work Model
πŸ“ Mountain View, CA
Employment
πŸ’Ό Full-Time Direct
Recruitment Type
πŸ›‘οΈ Direct to HR Pipeline
πŸ›‘οΈ
Human-Verified Opening: Inspected by Sarah Jenkins, CIPD • RemoteVault Editorial Team. Authenticated directly from SWI - Innovation Delivered's hiring pipeline • Zero recruiter markups or candidate fees. Verification Standards →

πŸ“‹ Role Overview & Responsibilities

Penetration Tester (Android & Cloud)

Job Description:We are looking for a Penetration Tester (Android & Cloud) to join our team.The Development QA (DQA) lab has a dual role that is first to research new automation tools as well as take current tools and refine them to our needs.Second, act as a centralized QA group to provide quality assessment by creating comprehensive E2E test strategy for various Endpoint security solution development.This duality provides a unique opportunity to explore new concepts in different technologies and perform original research in quality domain.

Role & Responsibilities:Develop expertise in our product solutions, deep diving into design/architecture, & execute white box and black box penetration scenarios.Planning and Conducting Pen tests on Web application, Android platform, Android Apps, Backend APIs, and Cloud services.Research & simulate known security threats and attack vectors to test a system’s relative security.Threat modelling and scoping with stakeholders.Assist in creating and maintaining internal penetration testing and practice within QA team.Build Test harness & required Automation suites and validate attack vectors in Threat Lab.Creating and targeting journals publications on security research.Vulnerability logging and tracking until closure.Coordinate with program management, security architects at Internal & offshore sites.Stays up to date on current tools, technologies, and vulnerabilities to incorporate into testing practices.

Required Experience & Education:5+ years’ experience in Penetration testing - with 2+ years' experience in Android and 1+ year experience in Web Application.Degree in Cyber Security or Security relevant disciplines is a Plus.Comprehensive knowledge in Information Security practices on malware, phishing attacks, attack vectors and methods to protect against threats.OSCP or OSWA or OSWE or PNPT or BSCP or similar offensive security certification.Extensive Knowledge in Java or C or any relevant programming language.

Desired Qualifications:Experience in Endpoint security platforms.History in cyber security competitions or CTFs.Blog post on security research, walkthroughs or PoCs on security domain.Malware development or reverse engineering experience.Experience testing Endpoint Detection & Response (EDR), Extended Detection & Response (XDR) platforms, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR) or related products.

Necessary Skills & Attributes:Self-motivated individual with the ability to thrive in a team-based or independent environment.Detail-oriented with strong organization skills.Ability to work in a fast-paced environment.Limited supervision and the exercise of discretion.

Requirements:Experienced Pen Tester- 5 years in this domain.Experience in Android- having done pen testing on any Android devices.2nd aspect is basically Web- so someone who has done pen testing on the web as well- black box, white box, or within these domains.API- on cloud or mobile devices, has they found vulnerabilities?Framework- there could be framework on mobile devices or applications? ON the kernel level? Have they found any?from top layer- CloudGo down to 2nd level to applications, kernel, etc.What tools did they use? If no tools, and this was done thru brute force?Experience with 360 degrees- not just from using tools, found thru exploits, understand the core & find back door.In terms of tools- hard to specify certain tools as these change in the marketAny experience finding vulnerabilities or bug bounty/bug hunting.Certifications re: Security- OSCP or any penetration related.One major thing to look for:If Information Security Analyst profile- that is more monitoring security/pen testing events - not looking for just an AnalystVs. a Pen Tester - more red teaming (more offensive side for this job)If someone has more exp - they will typically be a part of the red team.

Target Companies:IBM X-Force team, Cloud strike (as they have a dedicated security team), Trusted Security, or Security consulting firms- as they do this type of security penetration testing for companies.Or Security Consultants- as these are more known as ethical hackers.Some testing can only be done/run in office, as there is some malicious - so for this role, there may be some weeks/days where they may be required to work in office 5 days a week (when required) - so candidates should be flexible to work onsite daily.

Interview Process:1st round Virtual Video CallBasic Pen test Skills

2nd round onsite panel interviews – 3 interviewers40min Technical Pen testing skillset validation40min In-depth domain knowledge40min Team Fit

Frequently Asked Questions

How do I apply for the Penetration Tester position at SWI - Innovation Delivered? β–Ό

Click the “Apply for this Position” button on this page to submit your application directly to SWI - Innovation Delivered without recruitment intermediary fees.

Is this position eligible for remote work or visa sponsorship? β–Ό

This position is located in Mountain View, CA with potential relocation and sponsorship assistance depending on candidate qualifications.

Are there any candidate fees on Hirely? β–Ό

No. Hirely is completely free for candidates. We never charge registration fees or placement fees.

πŸ›‘οΈ Job Seeker Safety Advisory

Legitimate employers will never ask you to transfer funds, purchase equipment from unauthorized vendors, or pay application/visa fees. Hirely rigorously monitors listings, but always verify communication is from official corporate email domains.

Learn how to protect yourself against employment fraud →
← Explore Other Roles