Execute manual penetration testing engagements against a variety of web applications/services and software
Develop other security engineers
Advise management of violations or egregious negligence toward defined standards in targets tested
Provide actionable remediation feedback for findings and/or long-term risk mitigation guidance
Provide clear communication on the issue to developers and verify the efficacy of the fix
Partner with developers to drive improvement in application security as a result of security assessment engagements
Qualifications & Experiences
Hybrid work workplace. Must be based in the WBDs office, minimum three days /week.
A Bachelor's degree in Computer Science , Cybersecurity, or other related fields, from an accredited university or an equivalent professional experience may suffice in lieu of a Bachelors degree.
5 + years of experience in penetration testing, code review, bug bounty hunting, or red teaming/capture the flag experience.
Experience in scripting in Python or other languages to build automation tools .
5 + years of professional experience with security engineering practices such as in web application security, network security, authN / authZ protocols, cryptography, automation, and other software security.
Must be a t eam player with strong communication skills .
If you are excited to work in an international, fast-paced, multi-faceted media company are comfortable ensuring timely escalation, responsiveness and follow through to meet deadlines .
are knowledgeable of, and understand, the risk-based business impact approach to cybersecurity.
are actively questioning and influencing actions needed to attain goals and targets.
are comfortable driving initiatives forward without having direct control of staff.