Principal Associate, Penetration Tester (Remote-Eligible)
Company: Capital One
Location: Richmond
Posted on: September 21, 2023
Job Description:
Center 3 (19075), United States of America, McLean,
VirginiaPrincipal Associate, Penetration Tester
(Remote-Eligible)Capital One Offensive Security reduces cyber risk
by uncovering vulnerabilities and weaknesses in the enterprise
cyber environment through coordinated ethical hacking and
penetration testing scenarios. This position works closely with
team members to plan, coordinate, execute and report on
sophisticated ethical hacking exercises, to identify cyber
vulnerabilities and reduce the risk posture of enterprise systems.
This role will be primarily responsible for performing application
and network security assessments and will make recommendations to
management on effective countermeasures.--The successful candidate
for this position will be part of an exciting and dynamic
environment to build and deliver industry leading ethical hacking
capabilities to continuously protect and defend Capital One brand,
systems and data. Offensive Security is part of the Cyber
Operations and Intelligence program and assists with identifying
opportunities to enhance Capital One's information security posture
against a broad range of cyber threats, and develop strategies to
most effectively address the threats.Capital One is open to hiring
a Remote Employee for this opportunity.Primary responsibilities for
this position include:
- Perform penetration testing of APIs, web applications,
networks, and cloud services, as well as related applications and
infrastructure.
- Assess Capital One's development practices and help drive
corporate security standards.
- Help triage and test application responsible disclosure
findings and newly disclosed vulnerabilities.
- Work with developers to improve the Software Development
Lifecycle (SDLC) for applications.Basic Qualifications:
- High School Diploma, GED, or equivalent certification
- At least 3 years of Penetration Testing experience
- At least 4 years of experience working in cybersecurity or
information technology
- At least 1 year of experience with public cloud environments
(AWS, Azure, GCP)Preferred Qualifications:
- Bachelor's Degree
- 5+ years of security testing experience--- (red teaming, cloud
security, application security, or network security)
- 5+ years of experience with threat modeling concepts and
frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE)
- Penetration testing experience with Internet of Things (IoT)
devices, mobile applications, or code review.
- Development experience with common scripting/programming
languages such as Python, Golang, and C#.At this time, Capital One
will not sponsor a new applicant for employment authorization for
this position.The minimum and maximum full-time annual salaries for
this role are listed below, by location. Please note that this
salary information is solely for candidates hired to perform work
within one of these locations, and refers to the amount Capital One
is willing to pay at the time of this posting. Salaries for
part-time roles will be prorated based upon the agreed upon number
of hours to be regularly worked.New York City (Hybrid On-Site):
$161,900 - $184,800 for Prin Assoc, Cyber TechnicalSan Francisco,
California (Hybrid On-Site): $171,500 - $195,800 for Prin Assoc,
Cyber TechnicalRemote (Regardless of Location): $137,200 - $156,600
for Prin Assoc, Cyber TechnicalCandidates hired to work in other
locations will be subject to the pay range associated with that
location, and the actual annualized salary amount offered to any
candidate at the time of hire will be reflected solely in the
candidate's offer letter.This role is also eligible to earn
performance based incentive compensation, which may include cash
bonus(es) and/or long term incentives (LTI). Incentives could be
discretionary or non discretionary depending on the plan.Capital
One offers a comprehensive, competitive, and inclusive set of
health, financial and other benefits that support your total
well-being. Learn more at the--. Eligibility varies based on full
or part-time status, exempt or non-exempt status, and management
level.No agencies please. Capital One is an Equal Opportunity
Employer committed to diversity and inclusion in the workplace. All
qualified applicants will receive consideration for employment
without regard to sex, race, color, age, national origin, religion,
physical and mental disability, genetic information, marital
status, sexual orientation, gender identity/assignment,
citizenship, pregnancy or maternity, protected veteran status, or
any other status prohibited by applicable national, federal, state
or local law. Capital One promotes a drug-free workplace. Capital
One will consider for employment qualified applicants with a
criminal history in a manner consistent with the requirements of
applicable laws regarding criminal background inquiries, including,
to the extent applicable, Article 23-A of the New York Correction
Law; San Francisco, California Police Code Article 49, Sections
4901-4920; New York City's Fair Chance Act; Philadelphia's Fair
Criminal Records Screening Act; and other applicable federal,
state, and local laws and regulations regarding criminal background
inquiries.If you have visited our website in search of information
on employment opportunities or to apply for a position, and you
require an accommodation, please contact Capital One Recruiting at
1-800-304-9102 or via email at
RecruitingAccommodation@capitalone.com. All information you provide
will be kept confidential and will be used only to the extent
required to provide needed reasonable accommodations.For technical
support or questions about Capital One's recruiting process, please
send an email to Careers@capitalone.comCapital One does not
provide, endorse nor guarantee and is not liable for third-party
products, services, educational tools or other information
available through this site.Capital One Financial is made up of
several different entities. Please note that any position posted in
Canada is for Capital One Canada, any position posted in the United
Kingdom is for Capital One Europe and any position posted in the
Philippines is for Capital One Philippines Service Corp.
(COPSSC).
Keywords: Capital One, Richmond , Principal Associate, Penetration Tester (Remote-Eligible), Education / Teaching , Richmond, Virginia
Didn't find what you're looking for? Search again!
Loading more jobs...