https://bayt.page.link/WrvXY3jHaxEe2XUd9
العودة إلى نتائج البحث‎

Principal Penetration Testing Engineer

قبل 5 أيام 2025/07/13
خدمات الدعم التجاري الأخرى
أنشئ تنبيهًا وظيفيًا للوظائف المشابهة

الوصف الوظيفي

Career CategoryInformation SystemsJob Description

Join Amgen’s Mission of Serving Patients


At Amgen, if you feel like you’re part of something bigger, it’s because you are. Our shared mission—to serve patients living with serious illnesses—drives all that we do.


Since 1980, we’ve helped pioneer the world of biotech in our fight against the world’s toughest diseases. With our focus on four therapeutic areas –Oncology, Inflammation, General Medicine, and Rare Disease– we reach millions of patients each year. As a member of the Amgen team, you’ll help make a lasting impact on the lives of patients as we research, manufacture, and deliver innovative medicines to help people live longer, fuller happier lives.


Our award-winning culture is collaborative, innovative, and science based. If you have a passion for challenges and the opportunities that lay within them, you’ll thrive as part of the Amgen team. Join us and transform the lives of patients while transforming your career.


Principal Penetration Testing Engineer


What you will do


Let’s do this. Let’s change the world. In this vital role has a strong focus on ensuring the organization's infrastructure, applications, and systems are secure from external and internal threats. As a senior-level position, this role involves not only hands-on penetration testing but also overseeing teams, setting testing strategies, and working closely with other security and engineering teams to implement long-term security improvements. The ideal candidate has in-depth knowledge of cybersecurity practices, experience in complex security assessment practices and strong leadership skills.[BB1] [MG2]


Roles & Responsibilities:


Ø Perform advanced security testing (e.g., penetration testing, code reviews) and ensure continuous security monitoring across the organization’s IT landscape.


Ø Identify vulnerabilities in networks, systems, applications, and infrastructure through hands-on penetration testing.


Ø Attempt to exploit discovered vulnerabilities to demonstrate their impact and prove their existence (e.g., retrieving sensitive data, elevating user privileges, or gaining access to admin functionality).


Ø Perform assessments on web applications, cloud environments, and network infrastructure.


Ø Use automated tools and manual techniques to identify security weaknesses.


Ø Conduct advanced post-exploitation tasks to simulate real-world attack scenarios.


Ø Build or modify existing penetration testing tools to streamline testing processes.


Ø Implement automation frameworks to improve the efficiency and repeatability of vulnerability assessments and penetration tests.


Ø Guide junior penetration testers in techniques, toolsets, and reporting.


Ø Assist in developing the skills of the cybersecurity team through formal and informal training sessions.


Ø Review and ensure the quality of penetration testing reports and findings of junior testers.


Ø Work with third-party security vendors for audits, product testing, and external assessments when required.


Ø Use automated tools (e.g., Burp Suite, OWASP ZAP, or Acunetix) to identify common vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and others.


Ø Document identified vulnerabilities in detail, explaining how they were found, their severity, and their potential impact. Include proof-of-concept (PoC) for critical vulnerabilities.


Ø Offer actionable, practical solutions for fixing vulnerabilities, such as secure coding practices, configuration changes, or security controls.


Ø Use risk-based prioritization, categorizing issues by their severity and business impact (e.g., high, medium, low) to help the organization focus on the most critical issues.


Ø Continuously learn about the latest vulnerabilities, exploits, and security trends.


Ø Present the findings to stakeholders, security teams, and management, explaining the business risk and potential impacts of the vulnerabilities discovered.


Ø Provide broader application security recommendations, such as adopting secure development frameworks, improving logging and monitoring, or enhancing incident response capabilities.


Ø Provide guidance and feedback on the organization's security policies and incident response plans based on findings from penetration tests.


Ø Serve as a trusted advisor on key security decisions and risk management.[BB3] [MG4]


Familiarity with industry standards and compliance requirements (e.g., PCI-DSS, NIST, ISO 27001) and their relevance to penetration testing.


Since the role will be technical, I recommend downplaying (not removing) strong leadership skills. [BB1]


No disconfirm. Accept edit. [MG2]


Same as before, downplaying business facing interaction to focus on technical expertise. We can handle interaction with senior leadership. [BB3]


No disconfirm. Accept edit. [MG4]


What we expect of you


We are all different, yet we all use our unique contributions to serve patients.


Master’s degree and 8 to 10 year of experience in Computer Science, Cybersecurity or Information Systems related field OR


Bachelor’s degree and 10 to 14 year of experience in Computer Science, Cybersecurity or Information Systems related field OR


Diploma and 14 to 18 year of experience in Computer Science, Cybersecurity or Information Systems related field


Must-Have Skills:


  • Strong knowledge of common vulnerabilities (e.g., OWASP Top 10, SANS Top 25), network protocols, encryption standards, application security and common penetration testing methodologies (ISSAF, OSSTMM, PTES).


  • Familiarity with tools like Burp Suite, OWASP ZAP and Metasploit.


  • A deep understanding of web application architecture, databases, and authentication mechanisms.


  • Ability to think critically and creatively when testing and attempting to exploit vulnerabilities.


Preferred Qualifications:


Good-to-Have Skills:


  • Experience with threat intelligence and incorporating emerging threats into penetration testing practices


  • Proficiency in scripting and automation (e.g., Python, Bash) is a plus


Professional Certifications (please mention if the certification is preferred or mandatory for the role):


  • Preferred: OSCP, OSWE, OSWA, eWPTX, GWAPT, GXPN


  • Preferred: CISSP


Soft Skills:


  • Excellent analytical and troubleshooting skills


  • Strong verbal and written communication skills


  • Ability to work effectively with global, virtual teams


  • High degree of initiative and self-motivation


  • Ability to manage multiple priorities successfully


  • Team oriented, with a focus on achieving team goals


  • Strong presentation and public speaking skills


What you can expect of us


As we work to develop treatments that take care of others, we also work to care for your professional and personal growth and well-being. From our competitive benefits to our collaborative culture, we’ll support your journey every step of the way.


In addition to the base salary, Amgen offers competitive and comprehensive Total Rewards Plans that are aligned with local industry standards.


Apply now


for a career that defies imagination


Objects in your future are closer than they appear. Join us.


careers.amgen.com


As an organization dedicated to improving the quality of life for people around the world, Amgen fosters an inclusive environment of diverse, ethical, committed and highly accomplished people who respect each other and live the Amgen values to continue advancing science to serve patients. Together, we compete in the fight against serious disease.


Amgen is an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other basis protected by applicable law.


We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.


.

لقد تجاوزت الحد الأقصى لعدد التنبيهات الوظيفية المسموح بإضافتها والذي يبلغ 15. يرجى حذف إحدى التنبيهات الوظيفية الحالية لإضافة تنبيه جديد
تم إنشاء تنبيه للوظائف المماثلة بنجاح. يمكنك إدارة التنبيهات عبر الذهاب إلى الإعدادات.
تم إلغاء تفعيل تنبيه الوظائف المماثلة بنجاح. يمكنك إدارة التنبيهات عبر الذهاب إلى الإعدادات.