Job Description
Brief description of the role:
- The role is for an Intermediate penetration tester for the Reboot Hiring Program, who will be involved in all sorts of pen testing sources, right from Web, API, thick clients, and printer mobile apps/drivers testing and red teaming, join us to embark on a diverse and exciting career path in a dynamic, high-tech environment. Our teams are creative and friendly, providing a wide range of CyberSecurity services at HP.
What a Penetration Tester does at HP:
- The role is part of a talented team of security engineers and architects within HP Cybersecurity’s Architecture & Security Engineering team. Our security engineers are responsible for ensuring the security of HP products, solutions, and infrastructure. Our security engineers primarily perform manual testing with the assistance of automated tools to identify a complex set of vulnerabilities across a wide range of products and technologies.
Responsibilities:
- Identifies HP system vulnerabilities, attacks, and threats, analyzes security incidents, and threats, and designs appropriate countermeasures.
- Performing manual testing, software composition analysis and code scanning is necessary.
- Uses knowledge of the HP environment to scope the extent and impact of any vulnerability, attack, or breach.
- Consults development and product teams on vulnerability remediation.
- Develops, enhances, and maintains HP’s security solutions based on HP security system analysis, research, and incident resolution.
Individuals who do well in this role at HP, usually possess:
- Ability to manually review code, along with the use of automated testing tools, such as Burp Suite, is essential to locate flaws in pen testing
- Search for weaknesses in common software, web applications and proprietary systems
- Research, evaluate, document, and discuss findings with Cybersecurity, application, product, and management teams
- Review and provide feedback for information security fixes
- Establish improvements for existing security services, including hardware, software, policies, and procedures
- Advanced understanding of Cybersecurity and IT security risks, threats, and prevention measures
- Advanced understanding of relevant programming and scripting languages (Perl, Python, PowerShell, HTML, JavaScript, etc.)
- Advanced security system analysis skills
- Advanced understanding of security standards and best practices
- Advanced understanding of networking and network security
- Advanced understanding of network monitoring and protocols
- Advanced understanding of:
- Off-the-shelf vulnerability assessment products and tools.
- Platform and application-layer penetration testing techniques.
- Adversary techniques, tactics, protocols, and related countermeasures.
- Dynamic and static malware analysis techniques.
- Memory analysis techniques.
- Experience with mobile devices and other hardware testing.
Education and Experience Required:
- We are inviting women currently on a career break, with a minimum of 2 years of experience in Full Stack Software Development, Software Testing, or Network Security, who are ready to re-enter the workforce.
HP is committed to supporting a smooth transition back to the corporate world through an on-the-job training program in the dynamic field of Cybersecurity Penetration Testing.