Pentest Product Associate
This product-focused security role operates an AI-driven DAST agent, develops cloud-native detection and attack logic, validates complex findings, and researches emerging threats. It requires at least two years of application security or penetration-testing experience plus strong cloud, web, scripting, and security-tool expertise.
About the job
Responsibilities
- Develop advanced detection algorithms to classify cloud technologies and fine-tune attack policies for identifying and exploiting vulnerabilities.
- Analyze cloud services, APIs, and log payloads to validate complex attack paths, reduce false positives, and support compliance with industry standards.
- Research novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for a DAST engine.
- Collaborate with Research, Backend, and R&D teams to turn operational insights into product features.
Requirements
- 2+ years of hands-on experience in application security or penetration testing.
- Proficiency with enterprise security tools such as Burp Suite, OWASP ZAP, or Acunetix.
- Knowledge of networking concepts, the OSI model, and cloud infrastructure such as AWS, Azure, or Google Cloud.
- Hands-on experience with Linux, Windows, Docker, Kubernetes, web protocols, and authentication mechanisms.
- Strong command of HTTP/S, REST, GraphQL, OAuth, and SAML.
- Proficiency in Python, Bash, or Go for automating security tasks and interacting with codebases.
- Ability to diagnose complex logs and scans and distinguish tool failures, configuration issues, and valid security findings.
- Self-motivated, collaborative, and able to communicate high-stakes security concepts effectively.
Nice-to-haves
- Knowledge of AI/ML, LLMs, or reinforcement-learning agents in cybersecurity.
- SaaS and cloud experience with modern cloud-native architectures.
- Red-team experience, including simulated adversarial attacks and bypassing WAFs or other security controls.
Skills
Application Security, Penetration Testing, Burp Suite, Owasp Zap, Acunetix, AWS, Azure, GCP, Linux, Docker, Kubernetes, Python, Bash, Go, GraphQL
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Conduct end-to-end security research on emerging threats, CVEs, misconfigurations, and cloud attack surfaces, then turn findings into scalable detection capabilities. Requires at least five years of security research or related experience, strong scripting skills, and expertise in network and application security.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Leads information security governance, compliance, security operations, risk management, and incident response for a healthcare AI company. Requires 5+ years of security experience and hands-on expertise with major compliance frameworks, SIEM, incident response, and third-party risk.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.