Senior Managing Penetration Testing Consultant - X-Force Red
Role details
Job location
Tech stack
Job description
The Global Security Consultant will be part of the X-Force Red Offensive Security team. The consultant's primary duty is to perform penetration tests against clients' applications including web, mobile and thick-client.
Engagements typically range from two to four weeks. Secondary duties include assisting in the sales process with potential or existing clients, and acting as a client's primary technical contact for projects delivered by other consultants. X-Force Red consultants provide subject matter expertise in the form of research, tooling, and consulting engagements.
You should have in-depth of knowledge and experience in testing modern enterprise applications across a variety of frameworks and platforms. Identifying vulnerabilities in these applications and exploiting them to gain access to sensitive data or systems.
The consultant must be able to rapidly learn new technologies and processes with minimal assistance. There is a potential for 20% travel, including international travel. Travel depends on project requirements.
Current active clearance level or ability to obtain one is beneficial.
This role can be performed from anywhere in the US.
Required technical and professional expertise
Requirements
- 10+ years of penetration testing experience
- 10+ years of consulting experience
- Ability to perform penetration tests against web applications plus at least one of the following: internal networks, wireless networks, mobile applications, thick-client applications, embedded applications, hardware
- Programming experience in one or more of the following: Java, .Net, Python, or Ruby
- Strong understanding of networks, firewalls, protocols, routing, and security technologies
- History of presenting at regional or major security conferences
- History of published research, blog posts, or other publications
- Experience coordinating security testing projects with multiple consultants, * Effective communication and presentation skills
- The ability to lead large groups and be a primary facilitator
- Demonstrated written skills
- Drive to do research, publications, blogs, presentations, etc.
- Comfortable working in a project based / client serving model
- Ability to lead and shape client expectations
- Help drive pursuits and engage in complex deals, matching outcomes to expectations
- Ability to work easily with diverse and dynamic teams
- Ability to self-start, and work independently on projects
Preferred technical and professional experience
- Experience testing GenAI applications and LLM models
- Experience with testing SaaS platforms and applications - SAP, Salesforce, Oracle
- OSCP, OSEP, OSWE, OSED, OSEE, Burp Suite Certified Practitioner, or other technical certifications
- Experience in reverse engineering software or hardware
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.