> Markdown version of [/jobs/ext/1788548-security-assurance-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1788548-security-assurance-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Assurance Penetration Tester - **Company:** RELX Group plc - **Location:** Cambridge, MA, United States - **Salary:** $71,600.0 - $119,400.0 - **Contract:** Permanent contract - **Skills:** Training Data, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Software Documentation, Cyber Security, Information Leak Prevention, DevOps, Python (Programming Language), Nmap, Open Web Application Security, Windows PowerShell, Secure Coding, Software Engineering, Web Applications, Scripting, Cloud Platform System, Large Language Models, Metasploit, Operating System Security, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 10, 2026 - **Apply:** https://dejobs.org/x/x/020FE36389F34511BF3ED00E80524095/job/ ## About the Role * Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable. * At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus. * Foundational understanding of web application architecture, networking, and operating system security. * Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent). * Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS). * Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus. * Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations. * Exposure to SAST/DAST tools and secure code review practices is desirable. * Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations) ## Description Are you a collaborative Penetration Tester looking to work for a mission driven global organization? About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment. About the team - The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities. Responsibilities * Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking. * Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture. * Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices. * Maintaining program documentation, test records, and reporting artifacts. * Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed. * Performing peer review of penetration testing deliverables, including test plans, findings, and final reports. * Participating in scoping exercises and contributing to the selection of appropriate testing methodologies. * Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents. * Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning. * Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)