Senior Security Engineer - Penetration Tester
Job Description
The Information Technology Senior Management Forum is seeking a Senior Security Engineer focused on penetration testing and security validation across a wide range of enterprise systems. In this onsite Atlanta, GA role, you will help simulate real-world attack techniques, verify remediation, and communicate risk clearly to technical and non-technical stakeholders. The position also includes defensive discussion of findings, peer review, mentorship, and contributions to AI security testing initiatives.
Responsibilities
- Conduct penetration tests against enterprise applications, infrastructure, cloud platforms, AI systems, APIs, mobile applications, Active Directory environments, and other technology assets.
- Simulate real-world attack techniques to identify vulnerabilities, attack paths, misconfigurations, and security weaknesses.
- Perform validation and retesting activities to verify remediation and confirm risk reduction.
- Document technical findings with clear reproduction steps, supporting evidence, business impact, and remediation recommendations.
- Maintain testing artifacts and evidence to support regulatory, audit, and compliance requirements.
- Defend findings during discussions with application teams, technology leaders, and other stakeholders.
- Participate in escalation calls involving disputed findings, risk discussions, and remediation planning.
- Exercise sound judgment when assessing vulnerability severity and exploitability.
- Collaborate with internal and external testing teams to improve testing coverage and effectiveness.
- Stay current with emerging attack techniques, technologies, and industry trends.
- Contribute to AI security testing initiatives and emerging offensive security capabilities.
- Support AI model evaluation, testing, training, and security validation efforts.
- Provide feedback that improves testing methodologies, automation, tooling, and operational processes.
- Identify opportunities to increase testing efficiency, effectiveness, and scalability.
- Perform peer reviews of penetration testing reports and deliverables.
- Provide technical guidance and mentorship to junior security professionals.
- Collaborate across security, engineering, development, infrastructure teams, application teams, and various levels of management.
- Assist with standards, procedures, playbooks, and testing documentation.
- Support special projects and security initiatives aligned to individual expertise.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 7 years of experience in security engineering or related cybersecurity roles.
- Deep specialized knowledge in cybersecurity principles, theories, and concepts.
- Proven experience in software development lifecycle security practices.
- Deep knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
- 5+ years of penetration testing, red teaming, offensive security, vulnerability research, or related cybersecurity experience.
- Strong technical writing and communication skills.
- Ability to clearly articulate technical risks to both technical and non-technical audiences.
- Ability to independently manage multiple engagements in a dynamic environment.
- Experience defending technical findings and participating in challenging stakeholder discussions.
- Strong analytical and problem-solving skills.
- Ability to adapt quickly to changing priorities, technologies, and business needs.
- Experience with AI Security Testing and/or Mainframe Security Testing.
- Experience conducting penetration testing, red team, and security assessments across a variety of environments and technologies, including Active Directory, APIs, web applications, infrastructure, cloud platforms, mobile applications, thick/client-server applications, IoT devices, wireless networks, network security, social engineering, and physical security controls.
- Banking, financial services, or highly regulated industry experience.
- Experience supporting red team, purple team, or adversary emulation activities.
- Experience with scripting, automation, and offensive security tool development.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment
- Tax-preferred savings accounts
- 401k plan
- No less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment
- 10 sick days (also prorated)
- Paid holidays
- May be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan (depending on position and division)
Relevant Certifications
- Offensive Security (OffSec): OSCP+, OSEP, OSED, OSEE, OSWE, OSWA, OSAI
- GIAC: GPEN, GWAPT, GXPN, GRTP, GCFA
- ISC2: CISSP, CRIS
- Hack The Box: CPTS, Active Directory Penetration Tester, Web Exploitation Specialist, Web Exploitation Expert, Offensive AI Expert
- Equivalent offensive security, penetration testing, red team, exploit development, web application security, or digital forensics certifications will also be considered.
Location: Atlanta, GA (onsite)
Salary: USD 120,000 - 170,000 per yearly