Execute manual penetration testing engagements against a variety of web applications/services and software Develop other security engineers Advise management of violations or egregious negligence toward defined standards in targets tested Provide actionable remediation feedback for findings and/or long-term risk mitigation guidance Provide clear communication on the issue to developers and verify the efficacy of the fix Partner with developers to drive improvement in application security as a result of security assessment engagements Qualifications & Experiences Hybrid work environment. Must be based in the WBDs office, minimum three days /week. A Bachelor's degree in Computer Science, Cybersecurity, or other related fields, from an accredited university or an equivalent professional experience may suffice in lieu of a Bachelors degree. 5 + years of experience in penetration testing, code review, bug bounty hunting, or red teaming/capture the flag experience.
Experience in scripting in Python or other languages to build automation tools. 5 + years of professional experience with security engineering practices such as in web application security, network security, authN / authZ protocols, cryptography, automation, and other software security. Must be a t eam player with strong communication skills. If you are excited to work in an international, rapid-paced, multi-faceted media company are comfortable ensuring timely escalation, responsiveness and follow through to meet deadlines. are knowledgeable of, and understand, the risk-based business impact approach to cybersecurity. are actively questioning and influencing actions needed to attain goals and targets. are comfortable driving initiatives forward without having direct control of staff.