Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Security Analyst- Pen Testing image - Rise Careers
Job details

Security Analyst- Pen Testing

The Security Analyst- Pen Testing plays a critical role in facilitating continued growth and execution within our security practice. This highly skilled and detail-oriented Consultant will have deep knowledge in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Hardware Penetration Testing. The ideal candidate will be responsible for identifying vulnerabilities across software and hardware systems, advising on remediation strategies, and communicating findings clearly to both technical and non-technical stakeholders.

Primary Responsibilities:

  • Conduct in-depth SAST, DAST, and SCA assessments across a variety of application types (web, mobile, desktop, APIs).
  • Perform hardware penetration testing on embedded systems, IoT devices, and industrial control systems (ICS), including debug interface discovery, firmware extraction and analysis, and secure boot review.
  • Develop and maintain threat models, attack trees, and risk assessments for both software and hardware systems.
  • Identify and exploit vulnerabilities using both manual techniques and automated tools, simulating real-world attack scenarios.
  • Provide detailed technical reports and executive summaries tailored to different audiences, including developers, engineers, and leadership.
  • Collaborate with product and engineering teams to prioritize and remediate vulnerabilities, offering secure design and coding recommendations.
  • Participate in security architecture reviews and code reviews to identify potential weaknesses early in the development lifecycle.
  • Assist in the development and implementation of security testing methodologies, checklists, and standard operating procedures.
  • Conduct security tool evaluations and help integrate them into CI/CD pipelines for continuous security testing.
  • Lead or support red team/blue team exercises, tabletop simulations, and incident response drills.
  • Stay abreast of the latest security trends, vulnerabilities, and threat actor tactics, techniques, and procedures (TTPs).
  • Contribute to internal knowledge bases, training sessions, and technical workshops to upskill team members and clients.
  • Engage with clients to understand their security needs, define testing scopes, and deliver high-quality consulting services.
  • Ensure all testing activities comply with legal, ethical, and organizational guidelines, including responsible disclosure practices.
  • Develop and present organized report findings to technical audiences. 

Professional Qualifications Sought:

  • Bachelor’s degree in computer science, cybersecurity or another related field, desired or significant aligned experience. 
  • Overall experience working in a Pen Tester role in a diverse technical hardware and software environments for more than three years. 
  • Certifications such as: Certified Ethical Hacker (CEH), Certified Hardware Security Professional (CHSP), Certified Mobile and Web Application Penetration Tester (CMWAPT), Offensive Security Certified Professional (OSCP), Certified Information Systems Security Professional (CISSP) or other generally accepted security certifications, are a plus. 
  • Present openness to new ideas, approaches, and technologies to address core business needs and align to risk tolerance.
  • Exhibit good time management, and presentation skills in virtual and face-to-face environments. 
  • Consistently exhibit strong oral and written communication skills and the ability to present to groups of varying sizes and audiences in ad-hoc and prepared situations.

Technical Qualifications Sought:  

  • Three years of experience independently conducting in-depth SAST and DAST assessments across web, mobile, desktop, and API-based applications using tools such as Burp Suite, Zed Attack Proxy (ZAP) and Nessus. 
  • Referenceable history performing hardware penetration testing on embedded systems, IoT devices, including firmware extraction, reverse engineering and analysis utilizing tools like Binwalk and Ghidra.
  • Experience analyzing Android and iOS mobile application runtimes using both physical devices and emulators.
  • Hands-on experience developing and maintaining threat models, attack trees, and risk assessments for both software and hardware systems.
  • Knowledgeable in identifying and exploiting vulnerabilities using both manual techniques and automated tools, simulating real-world attack scenarios.
  • History of contributing to the development of detailed technical reports and executive summaries tailored to different audiences, including developers and engineers.
  • Experience collaborating with product and engineering teams to prioritize and remediate vulnerabilities, offering secure design and coding recommendations.
  • Successful implementation of security testing methodologies, checklists, and standard operating procedures.
  • Conduct security tool evaluations on CI/CD pipelines and cloud infrastructure for continuous security testing.
  • Stay abreast of the latest security trends, vulnerabilities, and threat actor tactics, techniques, and procedures (TTPs).
  • Contribute to internal knowledge bases, training sessions, and technical workshops to upskill team members and clients.
  • Engage with clients to understand their security needs, define testing scopes, and deliver high-quality consulting services.
  • Ensure all testing activities comply with legal, ethical, and organizational guidelines, including responsible disclosure practices.  

Travel

  • Must be available to travel four to six times per year, with no more than 24 days away from home in a calendar year.   

Employment locations: Although this is a remote position, we are only open to employment of individuals with their legal residence in the following states: Wisconsin, Illinois, Ohio, Michigan, Indiana, South Dakota, Iowa, Arkansas, North Carolina, Arizona and Florida.

 

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Long Term Disability
  • Training & Development
  • Work From Home
  • Work life balance
  • Great Culture

Average salary estimate

$95000 / YEARLY (est.)
min
max
$70000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User

Drive innovative fintech product design as a Product Design Lead at Lab49, blending strategy, creativity, and client collaboration to transform user experiences.

Seeking an experienced Process Improvement Analyst to optimize state processes and support the Department of Public Safety with innovative solutions.

Photo of the Rise User
Posted 21 hours ago

Drive impactful healthcare analytics projects and client success as an Analytics Consulting Manager at Komodo Health, a leader in data-driven healthcare insights.

Photo of the Rise User
ICF Hybrid Santa Fe, NM
Posted 22 hours ago

Experienced Archaeologist wanted by ICF to lead and support cultural resource management projects across the Mountain West, working remotely with interdisciplinary teams.

Photo of the Rise User
Neo4j Hybrid Remote: United States
Posted 12 hours ago

Innovate and architect cutting-edge AI and graph database solutions as an AI Solutions Architect with Neo4j, a pioneering leader in data analytics and graph technology.

Photo of the Rise User

Drive cutting-edge employee experience solutions as a Solution Architect with a top consulting and technology firm, blending technical expertise and client-facing skills.

Photo of the Rise User

Experienced healthcare transaction advisory leader needed to drive M&A engagements and business growth at Bennett Thrasher.

Photo of the Rise User
Posted 1 hour ago

Go Nimbly seeks a skilled RevOps Consultant to optimize sales technology stacks and processes for fast-growing companies in a remote, collaborative environment.

Photo of the Rise User
Posted 21 hours ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

An opportunity to leverage your ServiceNow expertise as a Sr. Technical Consultant driving impactful business transformation projects remotely for a global cloud leader.

Photo of the Rise User
Posted 7 hours ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Employee Resource Groups

A Senior Solution Consultant role at Salesforce focused on delivering innovative AI-driven CRM solutions and fostering client success.

Photo of the Rise User
Posted 21 hours ago

Experienced SAP S/4 HANA MM IM Lead Consultant needed to lead large-scale implementations and drive integrated supply chain solutions for a global enterprise.

Photo of the Rise User

Lead end-to-end supply chain planning initiatives as a Senior Manager at Accenture, driving efficiency and innovation for diverse manufacturing and consumer goods clients.

Photo of the Rise User
JLL Hybrid San Francisco, CA
Posted 15 hours ago

Experienced Director sought to lead change management and transformation consulting engagements for JLL’s real estate clients in a hybrid role based in San Francisco or Los Angeles.

MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
July 29, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!