Sr. Testing Engineer - Security
Description
- Develop and maintain methodologies and procedures in support of a world-class adversarial security program
- Research, plan, and execute penetration testing and red team operations to identify software/network/cloud vulnerabilities and other weaknesses in security controls
- Communicate risks to stakeholders and software/network engineers, advocating for mitigation
- 7 or more years experience on a pen test team or red team
- Hands-on experience performing pen tests with web application penetration testing tools (e.g., Burp Proxy Suite, OWASP ZAP)
- Hands-on experience with multi-function penetration testing tools (e.g., Kali Linux, Metasploit, Nmap, Wireshark, Aircrack-ng)
- Hands-on experience identifying, rating, and triaging web application security vulnerabilities (such as the OWASP Top Ten)
- Hands-on experience developing adversary courses of action using MITRE ATT&CK or similar frameworks
- Hands-on experience executing penetration testing tactics, techniques, and procedures used to identify vulnerabilities in web applications, servers, cloud infrastructure, and on-premises network infrastructure
- Strong programming/scripting skills
- Experience delivering findings to stakeholders and consulting with teams to get vulnerabilities addressed
- Excellent verbal and written communication skills
- Data-driven decision making and teamwork skills
- Hands on experience building and growing a penetration testing program combined with a willingness to build and lead our team
- Strong organizational skills e.g. project management, time management
- Bachelor’s degree in Computer Science, Computer Engineering, or Electrical Engineering
- Certifications relevant to adversarial security testing, like CEH, Pentest+, GPEN, and/or OSCP
Please note that base pay is one important aspect of a compelling Total Rewards package. The base pay range indicated here does not include any additional benefits or bonuses/commissions that you may be eligible for based on your role and/or employment type.
#LI-KB1
Why AppFolio
Grow | We enable a culture of high performance, where delivering results is recognized by opportunities for growth and compelling total rewards. Our challenging and meaningful work drive the growth of our business, and ourselves.
Learn | We partner with you to realize your potential by investing in you from the start. We're cultivating a team of big thinkers through coaching and mentorship with our best-in-class leaders, and giving you the time and tools to develop your skills.
Impact | We are creating a world where living in, investing in, managing, and supporting communities feels magical and effortless, freeing people to thrive. We do this by innovating with purpose while cultivating a culture of impact. We learn as much from each other as we do our customers and our communities.
Connect | We excel at hybrid work by fostering an environment that feels flexible, personal and connected, no matter where we are. We create space to fuel innovation and collaboration, and we come together to celebrate, connect, and succeed.
Paddle as One.
Learn more at appfolio.com/company/careers
Statement of Equal Opportunity
At AppFolio, we value diversity in backgrounds and perspectives and depend on it to drive our innovative culture. That’s why we’re a proud Equal Opportunity Employer, and we believe that our products, our teams, and our business are stronger because of it. This means that no matter what race, color, religion, sex, sexual orientation, gender identification, national origin, age, marital status, ancestry, physical or mental disability, or veteran status, you’re always welcome at AppFolio.